diff --git a/CHANGELOG.md b/CHANGELOG.md index 5e31e5ad5..028853db4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -17,2200 +17,122 @@ into the new version's section — see docs/releasing.md. ## [Unreleased] -> **v5 at a glance.** The CLI is built around one workflow: `socket-patch -> scan` patches dependencies by rewriting lockfiles so only the patched -> packages resolve to Socket-hosted, integrity-pinned copies (hosted mode is -> the default, and scan never prompts); `socket-patch vex` emits OpenVEX for -> vulnerability scanners; `socket-patch vendor` ejects the patches into -> `.socket/vendor/` for offline installs (it ejects a hosted project: no -> manifest needed); `socket-patch list` shows them. Hosted mode keeps no -> ledger — the lockfile edits are the whole change, and `rollback` restores -> each hosted package to its upstream registry entry. `get`, `remove` and -> `rollback` work in every mode; `apply` and `repair` are the agent-mode -> commands; `setup` is removed. - -> **Semver note:** this entry changes `rollback`'s default behavior, narrows -> the meaning of its existing `vendored: []` JSON key, makes vendored mode -> manifest-free, moves vendored cargo wiring from `.cargo/config*` into -> `Cargo.toml`, tags vendored cargo copies' versions with `+socket.` -> (visible to the patched crate as `CARGO_PKG_VERSION`), makes a bare `scan` -> run hosted mode without prompting, changes which patch scan picks when a -> package has several, makes `vex` -> refuse to attest stale ledger records and corrupt vendor ledgers, drops the -> hosted redirect ledger (`rollback` / `remove` now restore upstream registry -> entries and refuse where they cannot; `list`'s hosted `details.ledger` -> becomes `details.lockfiles`; scan's `redirectState` loses `ledger` / -> `ledgerKey`; `vendor_supersedes_redirect` and `hosted_revert_unsupported` -> are gone), and -> retries a throttled patch API (new error text, added waiting, a throttled -> package failing its legacy-proxy batch), and removes the `setup` -> subcommand — all -> MAJOR per CLI_CONTRACT.md's semver policy — so it ships as the next major -> release (v5.0). - -### Removed (BREAKING) - -- **`setup` is removed, with every install hook it wired.** `socket-patch - setup` (and `--check` / `--remove` / `--exclude`, `SOCKET_SETUP_EXCLUDE`) - is now an unknown subcommand: a clap usage error, exit 2. The hooks it - wrote were npm `postinstall` / `dependencies` scripts, the - `socket-patch[hook]` Python dependency (a `.pth` startup hook), a Bundler - plugin under `.socket/bundler-plugin/` plus a managed `plugin - "socket-patch"` Gemfile block, and Composer `post-install-cmd` / - `post-update-cmd` entries. Hooks already committed keep working, since - they only call `socket-patch apply`, which stays; delete them by hand to - stop them. The README's "Upgrading from `setup`" section lists each hook - and the commands to move to hosted mode or keep agent mode. Agent mode is now `socket-patch scan --mode agent` once - (commit `.socket/`), then `socket-patch apply` in CI after every install. - Hosted and vendored mode never needed a hook. -- **PyPI and RubyGems distributions are removed.** The `socket-patch` wheel - and launcher gem, `socket-patch-hook` wheel, and `socket-patch-bundler` gem - are no longer built or published. Their sources, package tests, publishing - workflows, wheel builder, and version-sync entries are removed. Install - the standalone binary via `https://install.socket.dev/patch` (preferred), - `cargo install socket-patch-cli`, or `npm install -g @socketsecurity/socket-patch`. - npm remains available for the official Socket CLI. Python and Ruby dependency - patching remain supported; see the README's migration instructions. -- **`vex` no longer drops agent-mode patches whose ecosystem has no - install hook** ("Property 7"). A manifest patch that verifies as applied - (or any manifest patch under `--no-verify`) is now attested whatever the - ecosystem. The `ecosystem_not_setup` `skipped` code, its stderr note and - its `no_applicable_patches` message are retired. A manifest's `setup` - object (`manual`, `exclude`) still parses and is kept on rewrite, but - nothing reads it. -- **The `patch_setup` telemetry event** is gone with the command. -- **Core crate:** the `setup` and `package_json` modules and the - `gem_setup` / `composer_setup` / `pth_hook` aliases are removed from - `socket-patch-core`, along with the setup-only `npm_family` table column - (`FileRow::detects_pnpm`) and `VLT_SETUP_MARKERS`. -- **v3/v4 compatibility spellings are gone.** - - The v3.0 legacy env names `SOCKET_PATCH_PROXY_URL`, `SOCKET_PATCH_DEBUG` - and `SOCKET_PATCH_TELEMETRY_DISABLED` are no longer read and no longer - print a deprecation warning. Use `SOCKET_PROXY_URL`, `SOCKET_DEBUG` and - `SOCKET_TELEMETRY_DISABLED`. - - The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden - no-op `scan --detached` flag (vendored mode is always manifest-free) are - removed. Both are now unknown-flag usage errors (exit 2). - - The hidden `--mode` values `host`, `redirect` and `vendor` on `scan` and - `get` are rejected; only `hosted`, `vendored` and `agent` are accepted. - The hidden `scan --apply` and `scan --vendor` spellings stay. -- **`get --one-off` and `rollback --one-off`** (and `SOCKET_ONE_OFF`) are - removed. They were never implemented and only failed with a usage error; - `--one-off` is now an unknown-flag error (still exit 2) and - `SOCKET_ONE_OFF` is ignored. -- **`.socket/packages/` package archives are no longer read.** Nothing has - written them for several releases. `apply`, `vendor` and `repair` stop - probing and staging the directory, and `apply`'s JSON `appliedVia` loses - its `"package"` value (`"diff"` or `"blob"` remain). The GC sweeps - (`scan --prune`, `rollback`, `remove`, `repair`) delete any leftover - `.socket/packages/` files whole (`rollback` and `scan --prune` still - report them as `removedPackageArchives`). -- **Core crate:** removed uncalled public helpers - (`bun_lock::snapshot_binary_workspace_artifacts`, `vlt_lock_sniff_ok`, - and several `lock_inventory::view` accessors) and the never-read - `DepOverride::berry_zip_url` field (a `berryZipUrl` key in a patch - reference still parses). - -### Changed (BREAKING): patch UI streamlining - -- **`list` on an empty project exits 0.** A project with no manifest and - no ledger record (normal for hosted mode) used to exit 1 with - `manifest_not_found`; it now prints `No patches in this project. Run - \`socket-patch scan\`.` (human) or the success envelope with - `events: []` (`--json`). Only an unreadable or invalid manifest fails. -- **Help is grouped by task**: patch (`scan`, `get`, `list`), undo - (`remove`, `rollback`), ship (`vex`, `vendor`), and agent mode - (`apply`, `repair`). `-h` keeps `--cwd`, `--ecosystems` and - `--offline`; `scan --prune` moves to `--help`. -- **Hosted and vendored `get` never prompt.** Like `scan`, they take the - top-ranked accessible patch per package with no picker and no - confirmation, in `--json` too (no `selection_required` outside agent - mode). Agent-mode `get` keeps its picker and `Download and apply N - patches?` prompt. -- **`get` usage errors exit 2** (were 1): `get`'s - `--id`/`--cve`/`--ghsa`/`--package` multi-select, - `--mode hosted|vendored --save-only` and a malformed forced identifier. - Every usage error now exits 2. -- **Human output:** warning lines no longer carry the `(code)` tag - (`Warning: …`, `GC: skipped: …`); the codes stay in the JSON envelope. - Error lines keep theirs (`Error (): …`). Hosted mode is called "hosted", not "redirect", in human - text (`Switched 2 packages to hosted patches; rewrote 1 file.`). npm's - `allow-remote` notice is one line (full text under `--verbose` and in - `--json`). Hosted and vendored runs share one numbered `Next steps:` - block. Every declined prompt prints `Cancelled; no changes made.`, and - scan/get share one paid-plan upsell line. -- **`-h` is short**: about eight options per command (`--json`, - `--dry-run`, `--cwd`, `--ecosystems`, `--offline`, `--yes` where the - command prompts, and the command's main flags); `--help` still lists everything. The deprecated - `scan --apply` / `--vendor` spellings are hidden from both (still - accepted). - -### Changed (BREAKING) - -> **Ledger-free hosted mode.** The first entries below supersede every -> earlier entry in this section (and under Added / Fixed) that describes -> the hosted redirect ledger (`.socket/vendor/redirect-state.json`): its -> writes, quarantine, per-purl reverts, whole-ledger replay, ledger -> records in `list` / `vex` / `scan`, and `vendor_supersedes_redirect`. -> Those describe intermediate v5 development states; the ledger-free -> contract here is what ships. - -- **Hosted mode keeps no ledger.** `scan --mode hosted` / `get --mode - hosted` (and the in-memory hosted engine behind the hosted bundle) write - ONLY their lockfile / registry-config edits: - `.socket/vendor/redirect-state.json` is never written — not on success, - not on failure — so a hosted project commits just its lockfile and config - changes (`Commit package-lock.json to keep the redirect.`). A pre-v5 - ledger on disk is ignored by scan (never read for planning, never - quarantined, left byte-identical); a re-run plans from the current lock - text and is idempotent. The in-run `scan --mode hosted --vex` attests from - the patch records this run fetched, and the gem / Python stale-install - probes judge only those (a purl whose record fetch failed is not judged - this run: `record_fetch_failed` now says the in-run VEX omits it and - `socket-patch vex` fetches it again once the API answers). -- **`rollback` and `remove` restore hosted pins to their upstream registry - entries.** With no ledger to replay, each hosted pin the lockfiles wire - (discovered like `vex` does: a hosted URL counts only on - `https://patch.socket.dev` or the `--patch-server-url` origin) is - rewritten back to the DEFAULT UPSTREAM registry entry for `name@version`, - re-resolving what the entry pins from the public registry (core - `patch::redirect::upstream`). Restored formats: `package-lock.json` / - `npm-shrinkwrap.json`, `yarn.lock` (classic and berry), `pnpm-lock.yaml` / - `shrinkwrap.yaml`, `bun.lock` and `vlt-lock.json` (npm registry version - document), `Cargo.lock` + `Cargo.toml` + the project cargo config - (crates.io sparse index), `go.mod` / `go.sum` (module proxy + checksum - database; a user's pre-hosted `replace` is not recoverable, so the - restore lands on the plain upstream module), `Pipfile.lock`, - `requirements.txt`, Hatch direct references, `poetry.lock`, `pdm.lock`, - `uv.lock`, PEP 723 script locks and `pylock*.toml` (PyPI JSON API), - `Gemfile.lock` / `gems.locked` + the Gemfile source block (rubygems.org - compact index; the declaration comes back as the exact pin), `composer.lock` - (packagist v2 metadata), `pom.xml` + the `.mvn` trusted-checksums lines - (no network — restores offline), and `nuget.config` + `packages.lock.json` - (nuget.org `contentHash`). A pin is all-or-nothing and nothing is written - until every pin resolved; `--dry-run` resolves exactly like a wet run. - **Refused**, with nothing written for the pin and the message `cannot - restore to its upstream registry entry: ; restore it from - version control instead (`git checkout -- `)`: every pin under - `--offline` except Maven, a registry that does not answer or no longer - describes the entry, a binary `bun.lockb` (for `rollback` / `remove`; see - the vendor takeover below), a composer entry that - is not packagist-sourced or whose `dist.reference` packagist no longer - serves, a gem whose upstream section is ambiguous or not rubygems.org, a - nuget id the restored config would not resolve from nuget.org alone, a - `pdm.lock` without `cross_platform` or a uv / pylock lock whose release has - a non-pure-Python-3 wheel, a uv lock whose options filter files or whose - registry is not PyPI's, uv 0.2 `[[distribution]]` locks, and any file - format the restore does not know. Rollback reports a refusal in - `hosted.failed[{purl, error}]` (exit 1, `partial_failure`; human `Error: - Cannot restore …`), `remove` as `hosted_revert_failed` before touching the - manifest. Human lines are `Restored to its upstream registry entry` - / `Would restore …`, and the prompt clause is `restore N hosted packages - to the upstream registry`. Scoped runs restore only the named pins (no - whole-ledger replay; `hosted.unsupported` is always empty and - `hosted_revert_unsupported` is gone), `--preserve-state` still restores - (`hosted_state_not_preservable`), and the vlt install heal still runs. - Side settings: a project `.npmrc` that is exactly `allow-remote=all` and a - `pnpm-workspace.yaml` that is exactly hosted mode's scaffold are deleted - once no lock entry needs them; otherwise the line stays with - `npm_allow_remote_left` / `pnpm_trust_lockfile_left` (v5 records no - provenance). New advisories: `maven_trusted_checksums_left`, - `nuget_default_config_left`, `upstream_uv_override_removed`. A pin - discovery cannot see (a lockless cargo pin, a nuget mapping with no - `packages.lock.json`, a Gemfile-only gem) is out of reach: restore those - files from version control. v4's `redirect_state_unreadable`, - `redirect_pnpm_trust_scaffold_modified` and - `redirect_npmrc_allow_remote_modified` are no longer emitted. -- **The Pipenv hosted redirect keeps the entry's `index`.** A hosted - `Pipfile.lock` entry is now `{"file" | "path", "hashes"}` plus every key - but `version` exactly as Pipenv wrote it — `index` included, present or - absent — so `rollback` / `remove` carry it back instead of guessing it - from sibling entries. Pipenv records `index` by release, Pipfile spelling - and locking environment (2018.11.26 writes it for a marker-excluded - package, 2022.12.19 does not; 2022.12.19 writes it for an `extras` table, - 2023.12.1 and later do not; no release writes it for a transitive - package), so no rule over the lock could re-derive it, and the guess left - those rollbacks off by one key. Measured on Pipenv 2018.11.26, 2020.11.15, - 2021.11.23, 2022.12.19, 2023.12.1, 2024.4.1, 2025.1.3 and 2026.8.0: a - `file` entry carrying `index` still installs the referenced wheel itself - (`install --deploy`, `sync`, `verify`); Pipenv 7–11 ignore `index` on a - `path` entry. The restore refuses when the entry's `index` (or the - Pipfile's explicit one) does not name a PyPI source in `_meta.sources`. -- **`list`, `vex`, `scan` and `repair` derive hosted state from the - lockfiles.** `list` shows one entry per hosted pin: JSON - `details.mode: "hosted"` plus `details.lockfiles: []` - (no `details.ledger`), human `Mode: hosted (wired in package-lock.json)`; - a pin carries only its uuid unless a pre-v5 ledger records the same purl - and uuid, and a ledger record whose pin is in no lockfile is no longer - listed. `scan --json`'s `redirectState` is now `{mode, records: [{purl, - uuid}], wiringLive}` built from the pins (no `ledger`, no - `records[].ledgerKey`) and is omitted when no lockfile pins a hosted - patch; `updates[]` folds the pins in (manifest > hosted pins > vendor - ledger), and `hosted_wiring_retained` keys on them. `vex` takes hosted - references from the lockfiles and their records from the API (online); - offline without a local record the pin is `record_unavailable`. A - malformed pre-v5 redirect ledger is now the WARNING - `redirect_ledger_corrupt` in `vex` (every form) and `list` — the run - continues — instead of `vex`'s exit-2 hard error. `repair` treats a - project with hosted pins (or a pre-v5 ledger) and nothing vendored as the - `redirect_only_project` skip, exit 0. A hosted URL on a staging host is - seen only with `--patch-server-url` (no ledger vouches for it any more). -- **`vendor` ejects a hosted project, and vendoring over a hosted pin - restores upstream first.** Standalone `vendor` with no manifest and hosted - pins in the lockfiles takes its patch set from those pins, fetches each - record from the patch API, vendors into `.socket/vendor/` and rewires - hosted → vendored (`Ejecting N hosted packages into .socket/vendor/...`, - `Would eject …` on a dry run). The eject is one planned, all-or-nothing - transition: every record is fetched and every upstream restore resolved - before anything is written (a failure is `eject_refused`, nothing - touched); a dry run writes nothing (`eject_planned`); the wet run - snapshots the files it touches and, if vendoring then fails, puts them - back so the project stays hosted (`eject_rolled_back`). It works from a - fresh checkout (no installed tree needed). `--offline` refuses it with - `offline_eject_unavailable` and makes no requests. A lock whose hosted - wiring discovery cannot attribute is refused with - `hosted_wiring_contested` by eject, `rollback` and `remove` (a warning in - `list`). Without hosted pins the no-manifest no-op is unchanged. Every vendored flow (`vendor`, `scan` / `get --mode - vendored`) that meets a hosted pin — any ecosystem, no longer just cargo, - golang and the npm family — first restores its upstream registry entry - with the same restore as `rollback`, so the vendor ledger records the - upstream entry and **`vendor --revert` returns to upstream, never to - hosted**. `vendor_takeover_reverted_redirect` (`… was hosted; restored its - upstream registry entry () before vendoring (mode takeover)`) and - the dry-run `vendor_would_revert_redirect` keep their codes; a refused - restore fails the purl `redirect_revert_failed` (`cannot vendor over the - live hosted pin: …`) and leaves it hosted. The cargo backend's - `hosted_redirect_live` refusal now names `socket-patch rollback` and - `git checkout -- Cargo.toml Cargo.lock` instead of the ledger. -- **Vendoring over a hosted binary `bun.lockb` works again** (Bun 0.8–1.1's - default lock and Bun 1.2's legacy lock; it was refused - `redirect_revert_failed` once the hosted ledger was gone). The takeover - and the eject rebuild each hosted remote-tarball record as Bun's npm - registry record for `name@version` from the registry's `dist.tarball` / - `dist.integrity`, re-derive the package metadata hash, drop the hosted - URL from the string pool, then vendor; `vendor --revert` returns the - pre-hosted lock. The hosted rewrite now keeps the registry record's - inactive bytes (padding, semver) in the tarball record it writes, and a - re-pin to a later grant's URL drops the superseded URL from the string - pool, so the rebuild is byte-exact — early writers' uninitialized padding included. - Where the hosted rewrite had to normalize the lock it marks it (in the - root package's resolution bytes, which no Bun reader reads): a binary - format 1 lock (Bun 0.1.1-0.1.6), promoted to format 2, is demoted back to - its exact format-1 bytes, and a lock whose workspace dependency behaviors - were normalized is refused with the `git checkout -- bun.lockb` remedy - instead of taken over non-exactly. `rollback` / `remove` keep refusing a - hosted `bun.lockb` pin with that remedy; an `--offline` vendor still refuses. -- **`vendor_supersedes_redirect` is removed.** The vendored flows no longer - warn about (or auto-reconcile, or unwind the `.npmrc` for) a stale hosted - ledger record: once the lock routes a package to `.socket/vendor/`, no - hosted state is left to go stale. `redirect_supersedes_vendored` (hosted - over a vendored package) stays, classified from the lockfile pins. -- **A pre-v5 hosted ledger is read for migration only, and `rollback` - retires it.** No command writes `redirect-state.json` any more; `list` - and `vex` read it only as an extra record source for a pin with the same - purl and uuid, and its edits are never replayed. `rollback` and `remove` - delete it once no lockfile pins a hosted patch (`legacy_redirect_ledger_kept` - warns when the delete fails), and a `rollback` in a project whose only - state is that file removes it and exits 0 (JSON - `legacyRedirectLedgerRemoved: true`) instead of failing on the missing - manifest. -- **Registry base overrides for the upstream restore.** Besides the existing - `SOCKET_NPM_REGISTRY`, `SOCKET_GOPROXY` and `SOCKET_PYPI_JSON_API`, the - restore honors new env-only knobs for mirrors and tests: - `SOCKET_CRATES_INDEX` (default `https://index.crates.io`), - `SOCKET_GOSUMDB_URL` (`https://sum.golang.org`; else `GOSUMDB` / - `GONOSUMDB` / `GOPRIVATE` as go reads them), `SOCKET_RUBYGEMS_URL` - (`https://rubygems.org`), `SOCKET_PACKAGIST_URL` - (`https://repo.packagist.org`) and `SOCKET_NUGET_URL` - (`https://api.nuget.org`). - -- **`repair` no longer rebuilds the vendor ledger from lockfiles.** A - lockfile that references `.socket/vendor///` with no entry in - `.socket/vendor/state.json` now fails with `vendor_ledger_missing` (an - artifact-level `failed` event with `uuid` and `details.{ecosystem,path}`; - exit 1) instead of re-synthesizing the entry (`details.ledgerRestored` is - gone). The rewired lockfile cannot supply the pre-vendor originals a - revert needs, so the remedy is restoring `state.json` from version - control (or `git checkout -- ` and re-vendoring). The unverified - npm "rebuild from the wired integrity" rung and the gem Gemfile wiring - reconstruction went with it; `rollback`'s missing-ledger error now asks - for `state.json` to be restored instead of naming `repair`. -- **`repair` re-vendors broken artifacts the way `vendor` does.** Missing - or corrupt vendored artifacts go through the same vendored backend as - `vendor` / `scan --mode vendored` / `get --mode vendored`, so under the - default `--vendor-source auto` the patch service's prebuilt artifact is - downloaded again, with a local build as the fallback (and the only - source under `--offline` / `--vendor-source build`). The result is still - verified against the ledger fingerprint before it counts as `rebuilt`. - Failure details are now `vendor`'s own (for example "no installed - package found on disk"), and a drifted installed copy of a gem or pypi - release variant is no longer force-overwritten by repair — it fails the - same installed-variant check `vendor` applies. Internally, `vendor`, `scan`/`get --mode vendored`, `vendor --revert`, - `rollback`'s vendored leg, `remove` and `repair` now share one - `VendoredBackend { apply, revert, repair }`. -- **Vendored runs refuse lock-text failures before downloading them.** - `scan --mode vendored` and `get --mode vendored` evaluate the vendor - backends' pure lock-text gates — pnpm, yarn classic and yarn berry - (coordinates; the lock / manifest reads and their line-ending, version, - `cacheKey` and `.yarnrc.yml` gates; override and `resolutions` - conflicts; the lock entry present and rewritable) and cargo's - `locked_version_mismatch` when it is the crate's first refusal — before - fetching patch views and pristine sources, so a package that will be - refused costs no network. This applies only to a package the vendor loop - would hand to its backend — one installed on disk, or one the lockfile - resolves to a verifiable registry source (the pristine fetch would - happen); a package absent from the lock and not installed keeps its - `skipped` / `package_not_installed` vendor event and its download - record, exactly as before. Such a package is now reported in the download - phase: `download.patches[]` records it as `action: "failed"` with the - backend's exact `errorCode` and `error`, `download.downloaded` drops and - `download.failed` rises by the number of such packages, and the vendor - envelope no longer carries their `failed` events (`vendor.summary.failed` - drops by the same number) nor, for lockfile-only packages, their - `vendor_fetched_missing` events. Exit code and the top-level `status` - are unchanged; the nested `vendor.status` becomes `success` when those - refusals were the vendor step's only failures (and when every selected - package is refused this way, the human arm prints `Nothing was - vendored: N patches failed (see above).`). - (The human `scan --mode vendored` arm still fetches the views its - baseline pre-check verifies.) Purls the lockfiles pin hosted keep the - vendor loop's refusal. Because no view is fetched, the - lock-text refusal now takes precedence over every outcome that came - from the view: a package that would also have hit a paid-access 403, a - failed view fetch or the no-applicable-files guardrail reports the lock - refusal instead. - The manifest-driven `vendor` command keeps its `failed` events but no - longer fetches the pristine source of a lockfile-only package it refuses - this way (no `vendor_fetched_missing` event, no registry request; with an - unreachable registry the gate's code replaces `vendor_fetch_failed`) — - again only when the lockfile resolves it to a verifiable source; one the - lock does not resolve keeps its `package_not_installed` skip. - On the polyglot monorepo fixture: 80 of 560 packages (74 - `vendor_lock_entry_not_found`, 4 `vendor_override_conflict`, 2 - `vendor_lock_entry_unsupported`) move to the download phase, saving 80 - view requests and 3 registry tarballs per run. - -- **Vendored cargo copies carry a tagged version: `+socket.`.** - The vendored copy's own `Cargo.toml` `[package] version` is rewritten to - the patch-tagged version (`1.0.4+socket.`; a version that already - has build metadata keeps it: `2.0.1+zstd.1.5.2.socket.`), and the - detached `Cargo.lock` entry records that tagged version with no - `source` / `checksum` — exactly the lock cargo itself writes when it - resolves the `[patch]` against the tagged copy (verified by building on - cargo 1.41 in docker and on current stable, and by the CI - `cargo-old-toolchains` leg on the 1.41 / 1.56 docker images — a local - run without those images only type-checks on rustup toolchains: - `--locked` builds, the patched bytes compile, a registry crate that - depends on the patched one (`^1`) resolves to the copy too, since cargo - ignores build metadata when matching requirements, and `cargo metadata` - reports the tagged version). Every lock reference that spells the old - version (`"cfg-if 1.0.4"`, v1's `"cfg-if 1.0.4 (registry+…)"`) is - rewritten to the tagged version, in lock formats v1–v4; a lock the edit - cannot keep consistent (a leftover reference in another spelling, a v1 - `replace`, an entry already at the tagged version) refuses before any - write with `cargo_lock_untaggable`, and a copy manifest whose version - literal cannot be rewritten byte-exactly fails the package with - `cargo_copy_untaggable`. The patch uuid of the copy cargo actually - builds is therefore recoverable from `Cargo.lock` alone (a config-level - `[patch]` override pointing elsewhere changes the locked version). **The - patched crate sees the tag in `CARGO_PKG_VERSION`** (and in - `env!("CARGO_PKG_VERSION")`-derived strings such as `--version` output - of a vendored binary crate): requirement matching on it - (`semver::VersionReq::matches`) is unaffected, but string comparisons - AND equality / ordering on a parsed `semver::Version` see the tag - (`semver` 1.x compares build metadata: `1.0.4+socket.` is not - `== Version::new(1, 0, 4)` and sorts above it). Re-runs are idempotent - (a dry run previews the tag as "would tag", and the wet run's - `cargo_lock_untaggable` / `cargo_copy_untaggable` refusals); a uuid bump - re-tags the copy and the lock; `vendor --revert` / `rollback` / - `remove` / GC / the hosted takeover restore the original lock byte for - byte (tag dropped with the `source` / `checksum`; a crate vendored - before any `Cargo.lock` existed has no originals, so only the tag its - first build locked is dropped). A user's own same-version path crate - that cargo later locks beside the tagged copy (an untagged sourceless - entry) is never mistaken for it: re-runs stay in sync, and the revert - restores the registry entry — spelled by its full id while the fork - shares its name+version, exactly as cargo writes it — without touching - the fork. GC keeps an entry whose lock tag is stale (another uuid) while - the manifest still wires this entry's copy: cargo re-locks any unlocked - build to the wired copy, and the next re-run retags. Projects vendored - before tagged versions (the pre-v5 `.cargo/config*` wiring, or an - untagged manifest wiring) are tagged by the next re-run or `repair` - (`cargo_version_tagged` note; a tag `repair` cannot write is the - `cargo_version_untagged` warning); a whole-tree file inventory recorded - for the copy is kept, and still verifies through exactly this uuid's - tag, so tagging never re-baselines it over unverified bytes. VEX - discovery treats the tagged lock version as the primary identity - (`pkg:cargo/@` is the tag stripped): a detached entry - tagged for a different uuid than the wiring's copy path is dead wiring - (not attested), and so is a copy whose own `Cargo.toml` is tagged for - another uuid than its path; a tagged entry no visible wiring names is - diagnosed unattributable; an untagged detached entry counts only beside - an untagged copy (the pre-tag vendored shape) — beside a tagged copy it - is some other crate cargo built, not attested. A patch that edits the - crate's own `Cargo.toml` verifies with the tag dropped — the tag being - this copy's own uuid, the same pin the inventory check applies, so a copy - tagged for another patch stays a mismatch instead of verifying clean - while VEX refuses it. -- **Vendored cargo wiring moved to `Cargo.toml`.** `vendor` / `scan` / - `get --mode vendored` write the `[patch.crates-io]` path entry into the - workspace-root `Cargo.toml` (beside the `Cargo.lock` it detaches) instead - of `.cargo/config.toml` / `.cargo/config`, so Socket scanners can recover - the patch uuid from the manifest alone and single-version wiring builds - on cargo older than 1.56 (the floor of config-file `[patch]`; proven on - cargo 1.41 with no network). TWO vendored versions of one crate need - cargo 1.45 or newer: from 1.45 `--offline` from an empty `$CARGO_HOME` is - enough (without `--offline` it first tries to update the crates.io index - and fails when that is unreachable), while cargo before 1.45 resolves - every source-less lock entry for a crate through one `[patch]` path and - fails closed on the other — see the `cargo_multi_version_old_cargo` - entry under Fixed. The edit is - format-preserving (comments, ordering, CRLF / mixed line endings, a - UTF-8 BOM and the trailing-newline state survive; a revert restores the - manifest byte for byte and keeps a user's own `[patch]` / - `[patch.crates-io]` headers). The key is always the Socket-owned - `-socket-` with `package = ""`, never the bare crate - name: cargo lets a config-file `[patch]` item (project, ancestor - directory or `$CARGO_HOME`) replace the manifest item with the same key - whatever its version, so a crate-named key could be silently shadowed — - and two vendored versions of one crate get distinct keys instead of - clobbering each other (the config wiring keyed by crate name let the - second overwrite the first). The ledger's `cargo_patch_entry` record now - names `Cargo.toml` (its `key` is the TOML key). New refusals, each before - any write: `cargo_manifest_unreadable`, `cargo_manifest_unparseable`, - `cargo_manifest_symlink_unsupported` (vendor and revert), - `cargo_manifest_not_workspace_root` (run from a workspace member, whose - `[patch]` cargo ignores) and `cargo_manifest_patch_source_alias` (the - manifest spells crates.io by URL in `[patch."https://github.com/rust-lang/crates.io-index"]`, - which replaces `[patch.crates-io]` wholesale); - `user_authored_patch_entry` now covers user entries in `Cargo.toml` and - in every cargo config file cargo merges (project, ancestors, - `$CARGO_HOME`) and matches by crate (`package` or key), sparing a path - patch that is provably another version. **Old wiring migrates - automatically**: a re-run or `repair` moves a Socket-owned - `.cargo/config*` entry into `Cargo.toml` (`cargo_wiring_migrated` note; a - migrating vendor re-run reports the package `applied`) and cleans a - config file / `.cargo/` the move emptied — a legacy entry that cannot be - removed fails the run and unwinds it (`cargo_legacy_wiring_kept`) — while - `rollback` / `remove` / `vendor --revert` / GC / hosted takeover remove - both spellings. Projects hit by the pre-v5 multi-version overwrite (a - detached lock entry nothing wired) are healed by a re-run or `repair` - (`cargo_wiring_restored`). User config entries are never touched. VEX - discovery reads the manifest first (key-agnostic), skips a manifest entry - that cargo ignores (a same-key project-config item or a URL-spelled - crates.io table replaces it), and still honors pre-v5 config wiring. The - hosted takeover's missing-ledger guard is now per version. -- **Binary Bun lockfiles are patched natively in place.** Hosted and vendored - modes read and rewrite `bun.lockb` formats 1–3 directly, including mode - changes, repair, and scoped rollback. Binary-to-text conversion, migration - ledger replay, and their warning codes and tests have been removed. -- **`rollback` is now the full-state dual of `scan`.** `scan` and `rollback` - are the batch primaries (`get`↔`remove` stay the single-patch duals): a - bare `rollback` restores the SYSTEM to unpatched across all three modes — - in-place file restore (agent), vendored unwire + artifact deletion + - ledger-entry drop, hosted lockfile-redirect unwind + redirect-record drop - — then removes the rolled-back entries from `.socket/manifest.json` and - GCs the now-unused blobs plus diff/package archives. No `--mode` needed: - state is inferred from the manifest, the vendor ledger, and the redirect - ledger, and rollback now runs manifest-less when a ledger holds work - (hosted-only and vendored projects; the truly-empty project - keeps the "Manifest not found" exit 1, and a wired-but-ledgerless project - errors naming `socket-patch repair`). Wet non-preserve runs confirm once - ("Roll back N patches, remove them from the local manifest, and delete - M vendored artifacts and their ledger records?" — auto-accepted under `--yes`/`--json`/non-TTY; - declining prints "Rollback cancelled." and exits 0). Drift-keeps, hosted - refusals/unsupported targets, corrupt ledgers, and a failed manifest - write exit 1 `partial_failure`; not-installed entries still exit 0. -- **`rollback --json`'s `vendored: []` array narrows** to vendor-owned purls - the run did NOT act on (today: the corrupt-vendor-ledger skip). Acted-on - entries move to the new always-present `vendoredReverted` / - `vendoredPreserved` / `vendoredKept` arrays; the envelope also gains - always-present `warnings[]` (`{code, detail}`, now populated), `hosted` - (`{reverted, failed, unsupported, editedFiles}`), `manifest` - (`{removedEntries, preserved}`), `gc`, and `paths` keys. -- **Vendored mode is manifest-free.** `scan --mode vendored` and - `get --mode vendored` never write (or read) `.socket/manifest.json`: the - selected patch records are fetched into memory and every vendor-ledger entry - carries `detached: true` plus the embedded `record` as its verification - source, so a vendored project's footprint is `.socket/vendor/**` only. The - former `--detached` opt-in is now the only vendored posture, and the flag - itself is removed (see "Removed"). JSON uses the detached download vocabulary for both - commands (`downloaded: N`, `detached: true`, `patches[].action` = - `downloaded` | `skipped` | `failed`). The vendor step vendors exactly what - discovery selected — the "whole manifest is vendored" re-vendor from a - committed manifest on an empty discovery is retired (`repair` verifies and - rebuilds committed vendored state) — and a legacy manifest record for a purl - a vendored run vendors is migrated into the ledger (dropped from the - manifest; an emptied manifest is left as `{"patches": {}}`). `list` now - reads the vendor ledger too, so a vendored-only project lists its patches - with a `Mode: vendored` label and exits 0 instead of `manifest_not_found`; - `scan --prune`'s lockfile-unused reconcile applies to every ledger entry - (the check is about the lockfile, not the manifest); and standalone `vendor` - with no manifest is a clean exit-0 no-op whose message names the missing - manifest (and the ledger entries `repair` verifies) instead of claiming - "No .socket folder found". -- **A bare `scan` runs hosted mode and never prompts.** With no `--mode` - (or legacy mode flag), `scan` rewrites lockfiles so the patched - dependencies resolve to Socket-hosted packages, exactly like - `scan --mode hosted`; under `--json` its result nests under `redirect` as - before. Only a `--prune` or `--global` scan with no mode is still - report-only (neither has a project lockfile to rewire); it prints the - report and `To apply these patches in place, run: socket-patch scan - --mode agent [PATHS]`. `scan` asks nothing in any mode: the download and - redirect confirmations and the free-tier patch menu are gone (and with - them the `Non-interactive mode detected` note), so `--yes` no longer - changes what `scan` does. Human `scan --mode hosted` prints the results - table and update detection like the other modes, fetches patch details - with the agent arm's progress counter and per-package warnings, and an - empty hosted discovery prints `No patches available for installed - packages.` and exits 0 without entering the redirect engine; a discovery - whose every offer is paid-tier for an org without paid access stops the - same way with `No downloadable patches (paid subscription required).`. -- **`get` defaults to hosted mode too.** `socket-patch get ` (and the - bare-UUID shortcut `socket-patch `) now redirects the package's - lockfile entry to its Socket-hosted patched copy, like `scan`. Agent mode - (manifest + in-place apply) is `--mode agent`, and stays the default with - `--save-only` or `--global`/`--global-prefix`. -- **scan picks the newest merged patch.** When a package has several - patches, `scan` (and `get`, and the `[UPDATE]` detection) now takes the - newest merged patch (one that fixes several advisories in one blob — the - package's cumulative fix) the account can download, whatever its - severity. A package with no merged patch keeps the old order: highest - severity, then newest. -- **`apply.lock` never outlives a command, and hosted mode takes it.** Lock - acquisition creates `.socket/` when missing; the lock file is unlinked - (while still held) and an otherwise-empty `.socket/` removed when the - command exits, dry runs included, so there is nothing to `.gitignore` and - `repair` no longer has a lock-cleanup step (a leftover from a crashed run is - reclaimed and removed by the next lock-taking command; a live holder is - still `lock_held`, exit 1). `scan`/`get --mode hosted` now acquire the lock - around their first wet write — never on `--dry-run` or when nothing would - be written, so previews create no `.socket/` — and report `lock_held` / - `lock_io` like the other lock holders (top-level `errorCode` on the hosted - JSON shape; a read-only project root or a file squatting on `.socket/` is - refused at the lock, before any file is touched, and a - vendored→hosted takeover over a symlinked wiring file is refused with - `redirect_symlinked_file_unsupported` before any revert). The lock guard - unlinks only the file it holds (a replacement planted by a non-cooperating - `rm` + `touch` is left for the next acquire), and a long `--lock-timeout` - wait behind a hot loop of short commands can no longer accumulate its - vanished-file retries into a spurious `lock_io`. Agent-mode `get` - and `scan --apply`/`--sync` hold one lock window across download → - manifest write → nested apply (the nested apply no longer re-acquires and - now inherits `--lock-timeout`/`--verbose`); `scan --prune` acquires once for its vendored - reconcile and manifest prune, and the GC legs of `scan --prune` and - `vendor` honor `--lock-timeout` and report a lock I/O error instead of - silently skipping on it. -- **Retired:** the legacy `.socket/cargo-patches` redirect takeover in the - cargo vendor backend (never shipped in a tagged release — such - `[patch.crates-io]` entries now refuse as `user_authored_patch_entry`) and - the `pypi_pipenv_invalid_wheel` refusal code (the Pipenv backend takes the - resolved version instead of parsing the wheel filename). -- **`vex` attests a ledger record only while a lockfile still wires it — - even under `--no-verify`.** A vendor-ledger entry whose artifact no - lockfile/config references any more is omitted as `vendor_unwired`, and a - redirect-ledger record whose hosted patch no lockfile references as - `redirect_unwired` (a manifest-owned purl falls back to agent-mode - verification instead). Previously a reverted lockfile plus a leftover - `.socket/vendor/state.json` / `redirect-state.json` kept attesting, and - `--no-verify` / `--vex-no-verify` attested every ledger record outright; - those flags now skip only the hashing, never the wiring, record-match and - conflict gates. A malformed or unreadable `.socket/vendor/state.json` is - now the hard error `vendor_ledger_corrupt` (exit 2 standalone, the host - command fails under `--vex`) — a malformed pre-v5 redirect ledger is only - the `redirect_ledger_corrupt` warning (see the ledger-free entries) — instead - of a warning after which vendored patches silently lost their - committed-artifact verification and detached records. - Lockfiles that wire one package to different patches attest none of them - (`wiring_conflict`), and when the lockfile wires a package to patch U, a - manifest or ledger record for it under another uuid is superseded. - -- **A throttled patch API is retried with a bounded backoff.** An HTTP - 429 or 503 from the patch API made the affected batch (or patch-list - query) fail on the first answer — likelier now that up to 32 requests are - in flight. Now every patch-API JSON call (batch search, per-package patch - lists, patch views and VEX record fetches, hosted package references) - retries a 429 / 503 up to 3 times: it waits as long as `Retry-After` asks - (delta-seconds or HTTP-date; one over 30 s is not waited out — the answer - is final at once — and one under the jittered first step, such as `0` or a - past date, waits that step), otherwise 0.5 s, 1 s, 2 s (steps capped at - 8 s, jittered into their upper half). All retries in a run must end - within a 60 s wall-clock window opened by the run's first retry, so a - throttled run adds at most about a minute however many requests it makes - (requests waiting in parallel each keep their retries). - `SOCKET_API_MAX_RETRIES=` (0-10) changes the count; `0` restores the - old single attempt. Nothing else is retried: 401/403 still trigger the - proxy fallback at once, and the public proxy's permanent `503 "Patch API - is not configured"` is never retried on any path (the batch still - degrades to per-package lookups at once; a per-package lookup answering - it is still skipped). Output folds in request order exactly as an - unthrottled run's. What breaks: a throttled run now takes longer before - it fails (up to ~60 s of added waiting); the error text changes — it - names why retrying stopped (`Rate limit exceeded (HTTP 429, gave up after - 3 retries). Please try again later.`, `API request failed with status - 503: (gave up after 3 retries)`, `(Retry-After 120 s exceeds the - 30 s retry cap)`, `(the run's 60 s retry window has closed)`); and on - the token-less legacy per-package proxy path (a proxy without `POST - /patch/batch`) a package still throttled after its retries now fails its - whole batch query — every package in that batch goes unchecked and the - batch is reported as failed (warning, or the all-failed error when it was - the only batch) — instead of that one package being skipped silently. - -- **scan honors the repo's socket.yml.** `projectIgnorePaths` (the - scanner's key) now also keeps `scan` from patching the matching projects, - in every mode and in the in-memory engine, whether or not the file has a - `patches` block (malformed values there only warn - `socket_yml_ignored_value`). See "socket.yml patch policy" in - CLI_CONTRACT.md. -- **Test and fixture trees are skipped by default when scan discovers - projects.** `test/ tests/ fixtures/ __fixtures__/ testdata/` (any case) - are built-in `ignorePaths` for discovered roots: hosted/vendored - PATH-glob matches (`scan 'services/*'`) and the in-memory engine's - detected roots (which used to skip them through a hard-coded, case- - sensitive segment list). A directory you name (`--cwd`, a literal PATH, - `projectRoots`) is not affected; `ignorePaths: ["!/e2e/tests/"]` - re-includes one, in memory too. -- **An invalid socket.yml fails scan.** An unparseable file, a misspelled - top-level `patches` key (`Patches`, `patchs`), a top-level merge or - aliased key, an invalid `patches` block (unknown key, wrong type, bad glob, `patches` - without `version: 2`), or `socket.yml` and `socket.yaml` that disagree - now fail `scan` before any request or write: exit 1, `errorCode: - socket_yml_invalid` / `socket_yml_ambiguous`, the key path and the fix - in the message. `--no-socket-yml` ignores the file for one run. -- **scan rejects a PATH outside the repository root** (exit 2): one socket.yml - policy per invocation. +v5 centers the workflow on `scan` (hosted patches), `vex` (OpenVEX attestations), +and `vendor` (committed patched packages), with `list` for inspection. See the +[v5 migration guide](docs/migrating-to-v5.md) before updating existing automation. + +### Breaking changes + +- `scan` and `get` default to hosted mode. `scan` never prompts, and hosted or + vendored `get` selects without an interactive menu. Explicit `--mode agent` + retains in-place patching; `get --save-only` and global targeting select agent + behavior by default. A mode-less global scan or `scan --prune` does not acquire + new patches, though `--prune` still cleans up obsolete state. +- Hosted mode writes no ledger. `list`, VEX, and update discovery read the live + dependency references. `rollback` and `remove` restore upstream registry entries + rather than replaying saved edits, and refuse where restoration is unavailable + (including offline operation and binary `bun.lockb`). Legacy hosted ledgers are + read only for compatibility and removed by full rollback. +- `rollback` restores dependencies and removes patch records and unused artifacts. + `--preserve-state`, also available on `remove`, keeps local state for reuse. + Hosted state has no local artifact to preserve. +- Vendored scans and targeted gets are manifest-free. The vendor ledger embeds + patch records; `repair` no longer reconstructs a missing ledger from lockfiles. + `vendor` can eject hosted pins when no agent manifest exists. Reverting an + ejected package restores upstream dependencies. +- Vendored Cargo patches use workspace-root `Cargo.toml` wiring and tagged + `+socket.` versions, visible to `CARGO_PKG_VERSION`. Re-running + vendoring or repair migrates older config-file wiring and untagged copies. +- `socket.yml` policy now constrains scans. Invalid patch policy fails before + requests or writes. Discovered test and fixture projects are excluded by + default; literal project targets skip those defaults. Hosted/vendored PATHs + outside the repository are rejected. +- Automatic patch selection prefers the newest merged patch, otherwise severity + and publication date. Existing patches change only when the new patch outranks + them; tier/UUID tie-breaking alone does not trigger replacement. +- `setup`, its publishing helpers, and the PyPI/RubyGems CLI distributions are + removed. Standalone binaries, Cargo, and npm remain supported; Python and Ruby + project support is unchanged. Remove old hooks using the migration guide. +- Removed `scan --redirect`, `scan --detached`, mode aliases `host`/`redirect`/ + `vendor`, the unimplemented `--one-off` flags, and the three legacy + `SOCKET_PATCH_*` environment aliases listed in the migration guide. + `.socket/packages/` archives are no longer consumed; cleanup removes leftovers. +- `list` on an empty project exits 0; `get` usage errors exit 2. Human help and + output are grouped by task, with diagnostic codes retained in JSON and verbose + output. Hosted JSON identifies lockfiles instead of a ledger; rollback's + `vendored` results contain vendor-owned entries only. See the + [CLI contract](crates/socket-patch-cli/CLI_CONTRACT.md) for exact schemas. +- VEX requires live hosted/vendored wiring and reports corrupt vendor ledgers. + Verified agent patches no longer require a `setup` hook for attestation. +- The core crate removes setup-related modules, obsolete public helpers, and the + unused `DepOverride::berry_zip_url` field. Patch references containing + `berryZipUrl` still parse. ### Added -- **`scan --max-new-patches ` rolls patches out gradually** - (env `SOCKET_MAX_NEW_PATCHES`; socket.yml `patches.maxNewPatches`). - Each run adds at most N patches to packages that had none, most severe first - (then by how many advisories a patch fixes), and defers the rest to the - next run; upgrades of packages that are already patched are never - capped, and `0` means upgrades only. Repeated scans on an unchanged repo - add the same packages in the same order and stop once everything is - patched. A patch that cannot land (not granted, refused by a preflight, - nothing in the lockfile to pin) never holds a slot, and a failed lookup - admits nothing new that run (`rollout_incomplete_lookup`). The project - directories of one scan share the budget. Works in hosted, vendored and - agent mode, `--dry-run` included; `scan --json` gains a top-level - `rollout` block (`maxNewPatches`, `counts`, ranked `deferred[]`) and - hosted mode lists deferred rows in `redirect.skipped[]` as - `rollout_deferred`. -- **The in-memory hosted engine paces rollouts too.** It (napi, - `hosted-bundle`) takes - `maxNewPatches`, `maxNewPatchesCap` and `inFlightPatches`, spends one - budget across every project root, and reports a session `rollout` block - and `ProjectResult.deferred[]`. -- **socket.yml patch policy (staged rollout).** A `patches` block in the - repo-root socket.yml narrows what `scan` patches: `enabled` (false = - report only), `includePaths` / `ignorePaths` (gitignore patterns matched - against each project's lockfiles, npm `ignore` semantics), - `ecosystems`, `packages` / `ignorePackages` (`--package` specs), - `minSeverity` (critical|high|medium|moderate|low, judged by the worst - advisory a patch fixes) and `maxNewPatches` (the per-run cap of - `--max-new-patches`). List flags (`--ecosystems`, - `--package`, PATHs) only narrow further; `--min-severity` beats the - file's floor and `--no-socket-yml` ignores the file. A package - that already carries a patch is never removed, upgraded or replaced by - the policy: it is held and reported under `policy.retained[]`. New flags - `--min-severity` / `SOCKET_MIN_SEVERITY` and `--no-socket-yml` / - `SOCKET_NO_SOCKET_YML`; every successful `scan --json` result gains a - top-level `policy` block (`source`, `sha256`, `minSeverity`, `filtered[]`, - `retained[]`) and the human output a `Policy (socket.yml): …` line that - names every skipped project and every critical/high patch the severity - floor held back. In memory, selection is two-phase: - `selectHostedScanPaths` takes the root policy files' text - (`policyFiles`) and `noSocketYml`, applies the full path policy and - returns `policyPaths`, `policySha256` and `policyError`; the session - takes `noSocketYml` / `minSeverity` / `policyPaths` / `policySha256` and - its result carries `policy` or `policyError`. - `get` ignores the policy and warns `policy_bypassed`. - -- **`scan --package `** (repeatable or comma-separated, env - `SOCKET_SCAN_PACKAGES`) scopes a scan to the named packages: a name - (`lodash`, `@scope/pkg`, `group:artifact`) or a purl with or without its - version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`); names compare - case-insensitively. -- **Hosted projects report patch updates from their lockfiles.** scan's - `updates[]` and `[UPDATE]` marker also see the hosted pins the lockfiles - wire (hosted mode keeps no ledger), so a hosted project still reports a - superseding patch. - -- **`apply` and `rollback` patch vlt installs in place.** A project - installed by vlt (`node_modules/.vlt/` or `node_modules/.vlt-lock.json`) - is detected as vlt ahead of any sibling bun, pnpm, yarn or npm marker, - and `apply` prints `Note: vlt layout detected…` in human mode. `scan`, - `get`, `apply`, `rollback` and `vex` find every package in vlt's store - (`node_modules/.vlt//node_modules/`) in every DepID era, - including transitive-only packages, aliases, git/remote/`file:` entries - and workspace members' link-only trees. `apply` and `rollback` reach - every store copy of a patched `name@version` (vlt's `~peer.`, - hashed-peer and modifier variants, and the legacy `··` / `·npm·` pair), - and every write replaces the file rather than writing through it, so - vlt 1.2's machine-wide store (hardlinked on Linux) stays untouched. The - store-copy failure note is now `store copy failed to patch` / - `failed to roll back` for pnpm and vlt alike. `--update` in a vlt - project suggests `vlt install @socketsecurity/socket-patch@latest`, and - in vlx's cache `vlx -y -- @socketsecurity/socket-patch@latest …`. -- **`rollback`, `remove` and the vendored takeover revert hosted vlt - redirects.** A `redirect_vlt_lock_node` ledger edit (written by the - depscan PR flow, or by `scan --mode hosted` once it rewrites - `vlt-lock.json`) puts the registry integrity and URL back on the node, - keeping whatever vlt re-laid since (a moved comma, a new flag or bins - slot, CRLF re-saved as LF). A node vlt has since re-locked away is - already reverted; any other change refuses with the `vlt-lock.json` - remedy. Peer and modifier variants are claimed per `name@version`. -- **`scan --mode hosted` and `get --mode hosted` redirect vlt projects.** - `vlt-lock.json` default-registry nodes of a patched `name@version` (every - peer and modifier variant, in every DepID era and CRLF lock) keep their - DepID and get the patched sha512 and hosted URL; `vlt.json` is read only. - vlt drives confirmation when its install state is present or no other - npm-family lock is; otherwise both locks are rewritten - (`redirect_vlt_sibling_lockfiles`). Before anything is written, each - artifact is fetched as vlt fetches it: a response vlt would reject - (re-gzipped, wrong sha512, HTTP error, unreachable) withholds the dep - (`redirect_vlt_artifact_unverifiable`, whose detail spells the URL's - grant-token level ``) instead of pinning a lock `vlt ci` - cannot install. After the write, stale installed copies of the - Socket-owned nodes (`node_modules/.vlt-lock.json` and their - `node_modules/.vlt/` entries) are removed so the next `vlt install` - extracts the patched packages; `rollback` and `remove` do the same for - the registry bytes. New `--no-vlt-install-cleanup` / - `SOCKET_NO_VLT_INSTALL_CLEANUP` keeps them, and the - `redirect_vlt_reinstall_required` advisory says what to run. A stale - copy of an optional dependency is never removed, because `vlt install` - would not put it back; the advisory says to run `vlt ci` instead - (after upgrading to vlt 1.0.5 or later when every dependency is - optional, since 0.0.0-30 … 1.0.4 would drop the installed copy). A - same-run `--vex` does not attest a vlt package whose installed copy is - stale or unchecked, whose lock a vlt release may ignore, or which also - resolves from a non-default registry. vlt ledgers require the socket-patch - release that adds vlt support. -- **`vendor` wires vlt projects.** A `vlt-lock.json` (lockfileVersion 0 - or 1) routes npm vendoring to the new vlt backend ahead of every other - lockfile. A direct dependency of the root or of a workspace member is - vendored as a patched package directory, - `.socket/vendor/npm//-/node_modules//`, so a - package that `require()`s its own name still resolves; its - `devDependencies` are dropped from the vendored `package.json`, and the - uuid dir's `.gitignore` re-includes the payload against the project's - own ignores while `.gitattributes` keeps EOL conversion off it. The - lock's node becomes a `file` node, its importer edges and the importers' - `package.json` specs move to the `file:` path, and every moved entry is - placed where vlt's own serializer puts it, so `vlt ci`, warm and cold - `vlt install --frozen-lockfile` keep the lock byte-identical and `vlt - install ` keeps the wiring (checked against vlt 1.2.0, 1.0.10, - 1.0.4, 1.0.0-rc.32 and 1.0.0-rc.14). A node whose only extra is one - peer context (a root dependency with resolved peers from vlt 1.0.8, a - workspace member's from rc.15) is vendored without the extra, as vlt - writes `file:` dependencies. Transitive targets - (`vendor_vlt_transitive_unsupported`), several instances of one - `name@version`, modifier variants, foreign registries, peer edges and - dependencies declared in several fields refuse before any write, as do - locks vlt - cannot read and specs that no longer match the lock - (`vendor_vlt_lock_out_of_sync`); a payload git would ignore refuses with - `vendor_artifact_gitignored` (git failing to answer warns - `vendor_artifact_gitignore_unchecked`), and a package already vendored through - another lockfile flavor with `vendor_flavor_changed`. `vendor --revert` - restores the registry node, edges and specs (keeping flags, trailing - slots and outgoing edge values vlt rewrote since) or keeps everything on - drift. Lock inventory reads `vlt-lock.json` too, Socket-hosted pins - included. Era-A locks (`··` ids, or URL-segment ids equal to a scalar - `registry`) warn `vendor_vlt_legacy_lockfile`. A vendored optional - dependency gets the new `vendor_vlt_reinstall_required` advisory: from - vlt 0.0.0-30 a plain `vlt install` keeps its installed upstream copy, - so it says to run `vlt ci` (or delete `node_modules` and run `vlt - install`); it also names any dependency whose `node_modules` link still - resolves to vlt's store. Reverting a vendored optional dependency (also - in a vendored-to-hosted takeover) gives the same advisory, since from - vlt 0.0.0-30 a plain `vlt install` then keeps the link to the removed - vendored directory. -- **Vendored vlt through every command.** `vendor`, `scan --mode vendored` - and `get --mode vendored` run the complete vlt vendored preflight (lock - version and layout, transitive, peer or foreign-registry targets, - dependencies declared in several fields, out-of-sync specs, a package - already vendored through another lockfile flavor, the installed copy's - `bundleDependencies` or duplicate `devDependencies`, a git rule that - ignores `.socket/`) before any patch is downloaded, anything is written, - or a hosted redirect is reverted for the takeover; the dry-run previews - report the same codes as `would_refuse`. A committed vlt directory - artifact is staged inventory-verified when nothing is installed (a fresh - clone), and vlt's own link to it is never taken as a pristine source. - After a hosted → vendored takeover the store copies vlt installed from - the hosted pin are removed (`redirect_vlt_reinstall_required`), except - optional ones, which the advisory reports as installed copies of the - vendored optional dependencies. `repair` - finds vlt references in `vlt-lock.json` and workspace `package.json` - files, rebuilds vlt directories against the inventory that leaves out - vlt's `node_modules/` links, restores a missing `/.gitignore` or - `.gitattributes`, and stamps reconstructed entries `flavor: "vlt"`. The - human output names the vlt committables and `vlt install`. A Bun lock - beside `vlt-lock.json` no longer triggers the Bun vendored preflight. - The git-ignore check refuses only a rule that ignores the vendored - uuid directory itself (such as `.socket/`), not one like `*.json` that - the directory's own `.gitignore` overrides. A takeover whose vendoring - then fails still removes the hosted store copies against the restored - registry pin. When vlt's link to the committed directory is the only - installed copy, `vendor` says so (`vendor_ledger_entry_missing`, run - `socket-patch repair`, when the vendor ledger lost the entry) instead of - reporting the package as not installed. -- **`vex` reads `vlt-lock.json`.** Manifest-less VEX (and the ledger - liveness gates behind `vex`, `scan`'s takeovers and the - `hosted_wiring_retained` advisory) discovers hosted vlt nodes (a Socket - URL and sha512 on a registry node, every DepID era) and vendored vlt - package directories, and verifies a vendored directory with the vlt - `package.json` exemption, including the out-of-sync check of the - installed link. A lock vlt cannot read (BOM, other `lockfileVersion`) - wires nothing. A hosted npm package is now judged by every store variant - of its installed copies (pnpm and vlt peer, modifier and registry-alias - instances), and a same-version instance on another registry (or a - Socket-shaped one that does not verify) keeps a vlt hosted pin from - attesting before install, as does a lock some vlt release discards (no - `lockfileVersion`, a pre-v1 legacy-id lock without vlt.json `modifiers`, - or a scalar `registry` outside a v1 lock with `registries.npm`), which - also warns `patched_ref_unattributable`. A vendored vlt directory - verified without its vendor ledger checks a devDependencies-stripped - `package.json` against the patched blob in `.socket/blobs`, and is - omitted as `vendor_manifest_unverifiable` when that blob is absent. -- **vlt support is proven against real vlt releases.** Every supported vlt - release (0.0.0-1 … 1.2.0, see `docs/testing/vlt-compatibility.md` for the - excluded ones) ran the five real-vlt capstones locally; CI now runs 35 of - those cells on every pull request (ci.yml's `e2e` vlt rows, each checked - by `scripts/check-vlt-legs.py` against the leg manifest), the vlt legs of - the required `hosted-e2e` production job (hosted and vendored), and the - advisory `vlt-compatibility.yml`: every capstone on every era of Linux, - macOS and Windows, the Node engine floors, the store linkers, - `scripts/backtest-vlt.py` against the production service, a cross-OS - `vlt-lock.json` comparison, and nightly `vlt@latest`, release-watchdog and - downgrade jobs. `vlt-serve-watchdog.yml` probes the public patch artifact - every 6 hours the way vlt fetches it. vlt releases are installed from a - sha512-checked `npm pack` (`scripts/install-vlt.sh`, pins in - `scripts/vlt-historical-integrity.json`). Hosted vlt projects stay - refused (`redirect_vlt_artifact_unverifiable`) until patch.socket.dev - stops re-encoding artifacts; vendored and agent mode work against - production today. -- **`--json` reports a failed patch-API query as a warning.** Under - `--json`, a batch query that failed (after the bounded retry above) while - others succeeded vanished from the envelope without a trace, exit 0, and - the agent / hosted / vendored flows' failed per-package patch-list - queries did the same; the human run already warned on stderr. Each is now - a run-level `warnings[]` entry carrying the human line's text: - `{code: "api_batch_failed", detail: "API batch of failed: - "}` (in batch order) and `{code: "patch_details_failed", detail: - "could not fetch details for : "}`. Additive: `status` and - the exit code are unchanged while some query succeeded, and the - all-failed error envelope and exit 1 still apply when none did. - -- **`redirect_yarn_berry_mixed_line_endings` and - `vendor_yarn_berry_mixed_line_endings`.** A `yarn.lock` (or, vendored, a - root `package.json`) that mixes CRLF and LF line endings — or holds a bare - CR — has no single ending to keep, and yarn itself rejects such a lock - under `--immutable` (YN0028) and rewrites it wholesale on its next plain - install. Both modes now refuse it before any write with a code naming the - line endings and the `yarn install` remedy; a revert never refuses on line - endings (a restored lock entry takes the terminator of the entry it - replaces). The real-yarn berry suites gained `SOCKET_PATCH_YARN_BERRY_EOL=crlf` - to run on CRLF files on macOS / Linux as yarn writes them on Windows, and - print a `BERRY-EOL||||yarn=…|flow=…` line per fixture - file — see [yarn berry compatibility](docs/testing/yarn-berry-compatibility.md). -- **Hosted npm redirects configure npm 12's `allow-remote` for you.** npm 12 - defaults to `allow-remote=none` and refuses (EALLOWREMOTE) a lock that - resolves patched packages from the Socket patch host. When `scan --mode - hosted` / `get --mode hosted` leaves a root `package-lock.json` / - `npm-shrinkwrap.json` redirected, it now writes `allow-remote=all` to the - project `.npmrc` — creating the file, or appending one line with the BOM, - CRLF and every other byte preserved — so a plain `npm ci` installs the - patched bytes on npm 12 (verified on npm 10.9.9, 11.20.0 and 12.1.0). The - edit is ledger-recorded (`redirect_npmrc_allow_remote`, `created` / `added`) - and `rollback`, `remove`, scoped unwinds and the hosted → vendored takeover - remove exactly what was added once no package-lock entry needs it (a - modified created file keeps its other lines: - `redirect_npmrc_allow_remote_modified`, reported by `rollback`, `remove`, - `vendor` and the vendored reconcile). An explicit user - `allow-remote=none` / `root` is respected — in the project `.npmrc`, in the - user / global / builtin npm config (a committed project line would - silently override that machine policy), or in an `npm_config_allow_remote` - environment variable (which beats every `.npmrc`) — and the warning names - where it was found. A symlinked, unreadable or bare-CR `.npmrc` is left - alone (and a symlinked one refuses an unwind before anything is written), - `--dry-run` writes nothing but previews the write — also for a vendored → - hosted takeover — and - `--no-npm-allow-remote-config` / `SOCKET_NO_NPM_ALLOW_REMOTE_CONFIG` opts - out. `redirect_npm_allow_remote` now fires on EVERY hosted npm run — - including when `.npmrc` already allows it — and always states the - tradeoff: `allow-remote=all` admits any url-resolved dependency, not just - Socket's, while the sha512 integrity pins stay enforced. The `.npmrc` - sniff now follows npm 12's measured grammar: only the exact key - `allow-remote` counts (an `allow_remote` / `ALLOW-REMOTE` line, which npm - ignores, previously silenced the warning), lines split on a bare `\r` as - well as `\n`, a `[section]` header only counts on the untrimmed line (as - in npm's `ini`), section bodies are not top-level (a section-scoped copy of - the line never makes the unwind ambiguous), and the value is - case-sensitive. Mode-preserving atomic writes now create their stage file - with the destination's permission bits, so a 0600 token-bearing `.npmrc` - is never staged world-readable. Vendored mode is unaffected - (npm gates `file:` tarballs by `allow-file`, default `all`). - -- **Manifest-less VEX: `vex` attests hosted and vendored patches straight - from the lockfiles.** `socket-patch vex`, and `apply` / `scan` / `vendor - --vex`, no longer need `.socket/manifest.json`, or the `.socket/vendor` - ledgers, to attest hosted and vendored patches. That covers a - depscan-opened PR, a clone that never committed its ledgers, and a lock-only - CI checkout. New read-only discovery (`socket-patch-core` `vex::discover`) - reads every supported root lockfile and config: - - npm: package-lock / shrinkwrap; - - pnpm: every lock generation, plus Rush locks; - - yarn classic and berry; - - `bun.lock` / `bun.lockb`; - - cargo: `Cargo.lock` + `Cargo.toml` + cargo config; - - Go: `go.mod` / `go.work` + sums; - - Python: uv, PEP 723 script locks, `pylock.toml`, poetry, pdm, - `Pipfile.lock`, requirements (+ `-r` includes), Hatch / PEP 621 direct - references; - - `Gemfile.lock` / `gems.locked`; - - `composer.lock`; - - maven: `pom.xml`; - - nuget: `nuget.config` + `packages.lock.json`. - - Each patch uuid is recovered from a Socket patch-host URL (or the - `--patch-server-url` origin) or a `.socket/vendor///…` path, - validated fail-closed. A lock that resolves the same package elsewhere - contests the wiring and blocks it. Records come from the manifest, then - the ledgers, then (online only) the patch API by uuid; nothing is written - to the manifest. `--offline` or a failed fetch omits the patch as - `record_unavailable`, and a record naming another patch or package as - `record_mismatch`. Evidence: vendored patches hash the committed artifact. - Hosted patches hash the installed copy the build consumes (the Go - replacement module, never the pristine cache copy), or, before any - install, attest from the lockfile's integrity pin. Unreadable or - unparseable lockfiles and rejected references surface as run warnings - (`lockfile_unreadable`, `lockfile_unparseable`, `patched_ref_invalid`, - `patched_ref_unattributable`) and never abort the run. Why a patch was - gated rides `warnings[]` too, so `--json` keeps it: a failed record fetch - (`vex_record_fetch_failed`, `vex_record_not_found`, - `vex_record_offline`), a stale-credential fallback to the public proxy - (`api_auth_fallback`, `get` / `scan`'s warning), a wiring conflict - (`vex_wiring_conflict`), a superseded record (`vex_record_superseded`) - and a dead ledger claim (`vex_claim_unwired`); a failed embedded `--vex` - adds one `vex_omitted` per omitted patch to the host command's - `warnings[]`. `apply --vex` and - `vendor --vex` with no manifest now write the document instead of exiting - 0 with none. A project with nothing wired anywhere keeps that calm exit, - and `apply --check` never generates. Manifest-less runs honor `vex - --dry-run` and `-O -` like every `vex` run, and show a transient - `Fetching patch records...` status line on a terminal. Per-PM support and - limitations: the README's "No manifest needed for hosted and vendored - patches" and CLI_CONTRACT.md's "Manifest-less VEX". -- **One lockfile reader per format, and one ledger-liveness rule.** - Discovery and the lock inventory read each lockfile through one reader - (the package-lock, composer.lock and Pipfile.lock entry walks, the hosted - rewriter's `pnpm-lock.yaml` grammar with one key grammar for every lock - generation, the backends' fail-closed `bun.lock` line grammar — so a hand - re-indented `bun.lock` is diagnosed `lockfile_unparseable` instead of - attested — one berry key splitter, which the vendored berry backend now - uses too, a shared `Gemfile.lock` model, the vendor backend's - `Cargo.lock` model, the Python lock and requirements-file readers the - rewriters use, with one exact-pin rule and one hosted pypi url - grammar). - `scan`'s cross-mode takeover warning `redirect_supersedes_vendored`, - `hosted_wiring_retained` and - `redirectState.wiringLive` now prove the live lock with the same - discovery and liveness rules `vex` gates attestations on, instead of a - looser text scan: a ledger record counts as live only while a lockfile - wires that package to the record's patch (a hosted url carrying its - uuid, or the exact vendored artifact the ledger names). That rule reads - EVERY lock's entry for the package (a PEP 723 script lock resolving it - from PyPI no longer vetoes the project lock's hosted entry) and a - recorded Gemfile with discovery's source-block grammar (a commented-out - `source … do` block no longer keeps a reverted record alive). The - shared readers - also change the lock inventory at the edges: a v1 `Cargo.lock`'s - `[metadata]` checksums now verify a crates.io fetch, `requirements.txt` is - read as pip's logical lines (continuations joined, comments cut, a BOM - dropped), a wildcard `requirements.txt` pin (`six==1.*`) is no exact - version, a Pipfile.lock hosted reference to an sdist, an `http://` origin - or a path-prefixed origin stays inventoried, a CRLF `pnpm-lock.yaml` is - inventoried (it used to read as having no packages), and a `poetry.lock` / - `pdm.lock` / `Cargo.lock` that is not valid TOML contributes nothing - instead of a best-effort line scan. The vendored berry backend splits a - multi-descriptor lock key the way yarn writes it, so a key mixing the - patched package with another descriptor (`"lp@npm:left-pad@1.3.0, - left-pad@npm:1.3.0"`) is refused `vendor_override_conflict` instead of - being read as one descriptor. -- **Standalone `vendor` embeds the patch record in its ledger entries too.** - Vendored mode (`scan` / `get --mode vendored`) already writes every entry - `detached: true` with its embedded `record`; the manifest-driven `vendor` - command now also writes `record` into `.socket/vendor/state.json` (never - `detached` — the manifest record stays authoritative while the manifest - covers the package), so a project it wired whose manifest is gone still - verifies, lists and attests offline: `vex` and `list` read - the embedded copy whenever no manifest entry covers the package, and - `repair` recovers the record without the API when there is no manifest at - all. Entries written by older releases keep working. -- **VEX product auto-detection covers Go, Composer, Maven, NuGet and - RubyGems projects**, after the existing git / `package.json` / - `pyproject.toml` / `Cargo.toml` probes: `go.mod` `module`, `composer.json` - `name`, `pom.xml` coordinates, the root's single `*.csproj`, the root's - single `*.gemspec`. Ambiguous roots yield no product rather than a guess. -- **Pipenv projects can use hosted patches, and vendored patches keep every - category.** `scan --mode hosted` rewrites every `Pipfile.lock` category - (`default`, `develop`, Pipenv 2022+ named categories) that pins the patched - release to the hosted wheel — `file` references for Pipenv 2018 and later, - `path` for 7–11 (probed once with `pipenv --version`; `SOCKET_PIPENV_MAJOR` - pins it), pipfile-spec < 6 refused — preserving markers, extras, unrelated - entries, the Pipfile and its content hash, with per-entry rollback - (`redirect_pipenv_entry`). Vendored mode keeps custom categories and extras, - uses `path` for wheels with extras (Pipenv 2022's file-URL bug) and refuses - installers older than 2018 (`pypi_pipenv_installer_unsupported`). A stale - Pipfile.lock only vetoes the sibling Python rewriters on a real pin/source - conflict (`redirect_pipenv_refused`); anything else is - `redirect_pipenv_skipped`. Measured across the last stable release of all - 18 published Pipenv majors — see `docs/testing/pipenv-compatibility.md` and - `scripts/backtest-pipenv.py`. -- **`Pipfile.lock` is inventoried.** Lock-only Pipenv checkouts (a fresh - clone with nothing installed) now discover their pins in every mode — - hosted redirects them, vendored fetches the pristine wheel by one of the - lock's recorded digests (`LockIntegrity::Sha256AnyOf`, resolved through - PyPI's JSON API and verified against the same digest) and agent/scan list - them as lockfile-only packages. Previously they discovered nothing and - exited 0. Socket's own references stay discoverable, so a re-scan of an - already-redirected or already-vendored lock-only checkout re-confirms it; - a lock that resolves only from private indexes is never looked up on - pypi.org. -- **Pipenv's out-of-tree virtualenv is discovered.** Discovery (`scan` in - every mode, `rollback`, `vex`) now finds `$WORKON_HOME/-[-]` (the - `.venv` file pointer, `PIPENV_CUSTOM_VENV_NAME` and `PIPENV_PIPFILE` - included) exactly as Pipenv 7 through 2026 place it, instead of falling - through to the global interpreter's site-packages. -- **Pipenv stale-install guard.** Pipenv never reinstalls a release that is - already present, so a hosted or vendored rewrite over a warm venv leaves the - upstream bytes installed; `redirect_pypi_stale_install` / - `pypi_pipenv_stale_install` now say so, naming the site-packages dir and - the verified remedy (`pipenv run pip uninstall -y && pipenv sync`, or - a clean `pipenv --rm && pipenv sync`), and the stale purl is excluded from - the same-run `--vex`. -- **PDM projects take hosted patches, and hosted and vendored patches share - one validated `pdm.lock` rewriter.** `scan --mode hosted` rewrites `pdm.lock` - to point the target `[[package]]` at the hosted wheel URL with the patched - SHA-256 (`redirect_pdm_lock_package`), and `scan --mode vendored` wires the - same unit to a committed wheel through the shared rewriter - (`utils/pdm_lock.rs`). Both preserve line endings and non-canonical spacing, - support the legacy `[metadata.files]` table and separate `extras` entries, - are idempotent, and leave `pyproject.toml` and `content_hash` untouched. - Supported lock formats are `2` (PDM 0.12–1.4) and `4.3`–`4.5.1` (PDM 2.8.1+; - PDM 2.8.0 writes the same `4.3` lock but still loses candidate identity, so - upgrade to ≥ 2.8.1); - the identity-losing `3.1` / `4.0`–`4.2` formats (PDM 1.8–2.7) and unknown - future formats are refused before any write (`redirect_pdm_refused` / - `pypi_pdm_lock_version_unsupported`), leaving the registry lock installable. - A `pdm.lock` written by PDM 0.x/1.x (lock format `2`) warns - `redirect_pdm_legacy_sync_required`: those releases have an upstream - freshness bug, so `pdm install` can regenerate the lock — use `pdm sync`. - Verified end-to-end against real PDM 0.12–2.29 across hosted, vendored and - agent mode on Linux, Windows and macOS; see - `docs/testing/pdm-compatibility.md` and `scripts/backtest-pdm.py`. When - several Python lockfiles coexist, `uv.lock` and `poetry.lock` drive hosted - PyPI redirects ahead of `pdm.lock`, so a leftover `pdm.lock` beside them - neither blocks a live redirect nor is falsely attested. A hosted lock-only - `pdm.lock` checkout is discovered and redirected (the lock inventory now - reads `pdm.lock`), and a re-scan after an external `pdm lock` rebases the - ledger's recorded edits onto the relocked text so `rollback` stays - byte-invertible even when PDM reflows the lock's line endings. -- **Poetry projects take hosted patches, and vendored patches now cover every - `poetry.lock` generation.** `scan --mode hosted` rewrites `poetry.lock` to a - `[package.source] type = "url"` pointing at the Socket-hosted, SHA-256-pinned - wheel (Poetry 1.0 through 2.x; Poetry 0.12 ignores URL sources and is refused - with `redirect_poetry_lock_unsupported`), and `scan --mode vendored` accepts - the legacy `[metadata.hashes]` (0.12) and `[metadata.files]` (lock 1.0/1.1) - layouts next to the 2.x `files` arrays, CRLF locks included. The rewrite keeps - every other byte of the lock — dependency metadata, groups, markers, extras - and the pyproject `content-hash` — and records independent rollback fragments - per patch, so `rollback` restores the recorded originals in any order. - Verified end-to-end against real Poetry 0.12.17, 1.0.10, 1.1.15, 1.2.2, - 1.3.2, 1.4.2, 1.5.1, 1.6.1, 1.7.1, 1.8.5, 2.0.1, 2.1.4, 2.2.1, 2.3.4 and - 2.4.3 in hosted, vendored and agent mode — see - `docs/testing/poetry-compatibility.md` and `scripts/backtest-poetry.py`. - Poetry releases before 1.4 neither verify local wheel hashes nor replace an - already-installed package at the same version; both modes surface that as an - advisory (`pypi_poetry_integrity_unverified`, `redirect_poetry_stale_install_risk`) - keyed on the lock's writer, and the hosted rewriter warns - `redirect_poetry_entry_not_found` when a lock has no entry for a granted - patch (uv parity). A rotated grant token or republished patch supersedes the - earlier hosted URL in place instead of being refused as a foreign source, - a future `lock-version = "2."` is rewritten like 2.1 on every path - (the vendored loader already accepted it), and a malformed - `[metadata.files]` / `[metadata.hashes]` value is refused instead of - panicking the scan. Rollback stays invertible across Poetry's own relocks: - the recorded package fragment carries its boundary header, so a unit that - Poetry 1.1/1.2 re-laid (source kept, inserted `files` line dropped) is - refused rather than mistaken for an already-reverted lock, a lock-1.0 - redirect restored by hand converges instead of refusing, and a re-scan - after such a relock REBASES the ledger's edits (pristine → current) - instead of appending a chain whose older links match nothing — which made - `rollback` and `remove` refuse forever. (#241) -- **Python patches survive uv lockfiles in both hosted and vendored modes.** - `scan --mode hosted|vendored` now rewrites native `uv.lock` together with - the paired `pyproject.toml` source and metadata, PEP 723 script locks - (`*.py.lock` plus the script's inline metadata), PEP 751 `pylock*.toml`, - and uv-compiled hashed `requirements.txt`, so `uv sync --frozen|--locked`, - `uv run --script`, and `uv pip sync --require-hashes` install the patched - wheel instead of the registry artifact. Verified against real uv binaries - from every 0.x release family (0.0 through 0.12) — first and latest release - of each plus every observed behaviour boundary — see - `docs/testing/uv-compatibility.md`: hosted mode covers requirements from - uv 0.0.5 and native `uv.lock` from 0.1.45 — the first release whose - `uv lock` writes one — through all three `[[distribution]]` lock shapes - and `[[package]]`; vendored native covers every `[[package]]` release - (uv ≥ 0.2.35), vendored requirements cover uv ≥ 0.1.24 (hash-enforced by - `uv pip sync --require-hashes` from 0.1.32 and by default from 0.5.x). - Follow-up hardening: - `vendor --revert` refuses to delete a vendored Python wheel a lock still - references when the ledger entry has no wiring to replay (the shape - `repair` rebuilds), a script or PEP 751 lock supplements rather than hides - `poetry.lock`/`requirements.txt` pins, symlinked locks are discovered, and - refused before any write (never rewritten in place — uv writes through the - link, an atomic rename would replace it; hosted - `redirect_symlinked_file_unsupported`, vendored - `pypi_uv_symlink_unsupported` / `pypi_lock_symlink_unsupported`), CRLF - locks keep their line endings in both the hosted rewriter and the vendored - uv backend (`pyproject.toml`, the rewritten `[[package]]` unit and the - appended `[manifest]` / `[package.metadata]` fragments, plus their revert), - and the hosted `[tool.uv.sources]` edit renders as a header after - `[project]` the way uv writes it. (#238, #239) -- **uv `--locked` survives the project shapes the plain fixture never - reached.** A package listed only in `[tool.uv] dev-dependencies` is now - classified as a direct dependency (it was wired as a transitive override - and its `requires-dev` entry left stale), and every duplicate - `requires-dist` / `requires-dev` entry for the package — extras, markers — - is repointed rather than only the first, so `uv sync --locked` and - `uv lock --check` accept the patched lock instead of exiting 2 and a plain - `uv sync` no longer rewrites it. `[tool.uv] constraint-dependencies` / - `build-constraint-dependencies` naming the package have their `[manifest]` - `constraints` / `build-constraints` entries repointed too (uv ≥ 0.5.6 - serializes them with the package's source; 0.2.37–0.5.3 reject the - repointed entry under `--locked`, so the repoint emits the advisory - `pypi_uv_constraints_require_uv_0_5_6`). The transitive - (override-dependencies) branch emits the advisory - `pypi_uv_override_requires_uv_0_5_6`: uv applies `[tool.uv.sources]` to - overrides only from 0.5.6, so on 0.2.35–0.5.3 `--frozen` installs the - patch but a plain `uv sync` reinstalls the registry wheel. The - `[[distribution]]`-grammar vendoring refusal now names the real reasons - (relative path sources unparseable through 0.2.6, rejected by `--locked` - and absolutized by `uv lock` / `uv sync` on 0.2.17–0.2.34) instead of - "records absolute paths". `scripts/backtest-uv.py` gains a project-variant - lane covering these shapes on every `[[package]]` binary and a - `--render-doc-table` mode that prints the doc's results tables from - `results.json`; its export lane reads `uv export` from stdout because - `--output-file` only exists from 0.4.7. (#239) -- **Unwired Python vendor entries revert safely.** `vendor --revert` / - `rollback` on a ledger entry without wiring to replay (the shape `repair` - reconstructs) skips the lock-reference guard under `--preserve-state` - (nothing is deleted, so nothing needs protecting), refuses fail-closed when - the project root cannot be listed or a lock's symlink target cannot be - read (instead of treating "could not enumerate locks" as "no lock - references it" and deleting the wheel), probes `-r` / `--requirement` - includes of `requirements.txt` alongside the root file — the orphan sweep - and `repair` see include-hosted pins too — and reclaims a genuinely - orphaned artifact directory whose lock is gone or whose ledger flavor is - unknown instead of failing forever. Hosted `scan` / `get`, `repair`, and - ledger-less `rollback` read candidate lockfiles through the FIFO-safe - reader, so a named pipe at a lockfile name no longer wedges the command in - `open(2)`. (#239) - -- **Path targeting on `scan` and `rollback`.** `scan [PATHS]...` scopes - discovery to packages with an installed copy under a matching glob - (ancestor rule: `scan packages/foo` covers the subtree; `*` never crosses - `/`; absolute patterns are the only way to reach `--global` stores); the - prune universe is never narrowed (`scan PATHS --prune` prunes exactly - what an unscoped run would), lockfile-only/vendor-ledger supplements are - excluded with a `path_scope_excluded_supplements` warning, an empty match - is a normal empty scan (exit 0, no GC). In hosted and vendored mode - (so also a bare `scan`) PATHS name project directories instead: each - directory or directory glob (`apps/*`) is scanned on its own, as if it - were `--cwd`, under a `== ==` header; the exit code is the worst of - the runs, a PATH that is not a directory is a usage error (exit 2), and - `--json` takes one directory. `rollback [TARGET]...` accepts - PURLs, UUIDs, and path globs (variadic, unioned); only path-SHAPED tokens - (separator, glob metachar, `./` prefix, absolute) become globs, so a - mistyped identifier stays a safe exit-1 error. A path target selecting - nothing is an error on rollback (exit 1) and an empty scan on scan - (exit 0); path targets select installed copies, and rollback restores - EVERY installed copy of a selected patch (`out_of_scope_copies_restored` - warning when copies live outside the patterns). -- **`--preserve-state` on `rollback` and `remove`** (env - `SOCKET_PRESERVE_STATE`): fully unpatch the system but keep the local - state for a later re-apply — manifest entries, vendored artifacts + - ledger entries (kept byte-identical; re-vendor re-wires from the live - lock) — and skip all GC. Hosted pins have no preservable state: they are - restored to upstream either way (`hosted_state_not_preservable` - warning). On `remove`, combining it with - `--skip-rollback` is a usage error (exit 2, flag- or env-sourced): the - combination would be a no-op — one flag keeps the tree and drops the - state, the other restores the tree and keeps the state. -- **Hosted unwind.** `rollback` restores every in-scope hosted pin to its - upstream registry entry, in every ecosystem — see "`rollback` and `remove` - restore hosted pins to their upstream registry entries" under Changed - (BREAKING); a pin that cannot be restored is refused with the `git checkout - -- ` remedy. -- **`remove` gains the hosted leg and full archive GC**: an identifier - matching hosted lockfile pins restores their upstream registry entries - (works manifest-less on hosted-only projects; a refused restore fails - `hosted_revert_failed` before the manifest mutation), and remove's - default GC extends from blobs-only to blobs + diff + package archives - (parity with rollback/repair/`scan --prune`). -- **`SOCKET_API_CONCURRENCY` paces `scan`'s patch-API requests.** `scan` - now keeps several patch-API requests in flight (8 authenticated, 4 on the - public proxy) instead of one at a time. Set this variable — clamped to - `1`-`32`, and on the public proxy only downward — when something in front - of the API caps in-flight requests per client (a self-hosted `--api-url`, - a corporate reverse proxy, a WAF, a CDN) and a scan starts losing - requests to it. `SOCKET_API_CONCURRENCY=1` restores one request at a - time. Unset, empty or non-numeric values keep the defaults. Results, - warnings and their order never depend on the setting. - - Two request-count consequences an operator may see before they read the - code, neither of which changes any output: - - - A vendored run fetches prebuilt archives ahead of the wiring loop. - The plan it fetches is exact — it is gated by the same pre-flight each - vendor backend runs before it would ask the service (an unsupported or - absent lockfile entry, an override conflict, a workspace gate), so a - package the run does not end up vendoring is never asked for: the - `POST /v0/orgs//patches/package` download grants, which can start - a server-side archive build and count against quota, are exactly the - one-at-a-time loop's (71 on a fresh depscan run, where an earlier - draft of the look-ahead issued 74). What changes is only their timing: - they are requested in one batch at the first planned package (see - "Fewer downloads in vendored runs"), and up to four archives are in - flight at once. `SOCKET_API_CONCURRENCY=1` turns the look-ahead off - entirely. - - A token revoked *mid-run* now costs the authenticated batch endpoint - the requests already in flight — up to the in-flight cap instead of - one — before the run downgrades to the public proxy. Their answers are - discarded and the connections are dropped mid-response, so the - endpoint's access log shows them; the downgrade warning, the patches - and the exit code are the same as before. +- `socket.yml` patch policy for paths, ecosystems, packages, severity, and per-run + limits. `scan --package`, `--min-severity`, `--max-new-patches`, and + `--no-socket-yml` support targeted and gradual rollout. Already-patched packages + retain protection when excluded; updates do not spend the new-patch budget. + Disk scans and the in-memory hosted engine share these rules. +- Manifest-free VEX discovery from hosted and vendored references, including fresh + checkouts. Product inference covers Go, Composer, Maven, NuGet, and RubyGems in + addition to existing formats. Embedded VEX supports the same evidence checks. +- vlt support across agent, hosted, and vendored workflows, with native installer + coverage and explicit version/layout refusals. +- Native binary `bun.lockb` reading and rewriting, alongside text `bun.lock`, + without invoking Bun or converting binary locks to text. +- Expanded Python lockfile support for uv, Poetry, PDM, and Pipenv, including + lock-only inventory, supported multi-version/marker shapes, and stale-install + diagnostics. Unsupported installer formats are refused before writes. +- npm 12 hosted `allow-remote` configuration and dual-lock handling, plus pnpm + trust-lockfile configuration. Explicit user settings are respected. +- Path targeting on scan and rollback, hosted update detection from lockfiles, + and configurable API request concurrency. + +See [ecosystem support](docs/ecosystems.md) and the +[compatibility guides](docs/testing/README.md) for format boundaries, integrity +limits, and required install commands. ### Fixed -- **`apply` no longer half-applies a patch that creates a file from a - diff-only cache.** A diff archive has no delta for a file the patch - creates, but the source check counted a cached diff archive as covering - the whole patch: `apply --offline` passed it, patched the modified files, - then failed on the created file's missing blob; online `apply` never - fetched that blob. Coverage is now per file (a diff covers only files - with a `beforeHash`), so `apply --offline` reports the patch as having no - local source up front and changes nothing, online `apply` fetches just - the created files' blobs, and a default (diff-mode) `repair` downloads - them too. Such a repair's `--json` envelope carries a second - `downloaded` (dry-run `verified`) artifact event with `mode: "file"` for - those blobs. -- **Hosted `scan` resolves more than 500 patches.** The package-reference - request is sent in chunks of 500 uuids, the endpoint's limit; a larger - scan used to fail with a 400. -- **Hosted nuget redirects survive a `` in `nuget.config`.** The - Socket source (and, in an existing ``, its - mapping) was inserted ahead of the section's ``, which NuGet - applies to everything read before it: `dotnet restore` then failed - NU1100 / NU1101 for the patched package. Both now land after the last - ``. - -- **nuget redirects and vendoring edit the config NuGet actually reads.** - NuGet reads the first of `nuget.config`, `NuGet.config` and - `NuGet.Config` in a directory. Hosted mode only knew `nuget.config` - and vendored mode missed `NuGet.config`, so on a case-sensitive - filesystem they created a fresh `nuget.config` that shadowed the - project's own file: its sources and mappings vanished and private - packages failed restore. Both modes now edit the existing spelling in - place. - -- **`rollback` fetches a before-blob that only a store peer variant - needs.** The before-blob gate now probes every pnpm and vlt store variant - copy the rollback restores, so an online rollback no longer fails - `Before blob not found` for a still-patched variant beside an - already-original copy. - -- **Re-vendoring under a newer patch never builds from the old patch's - artifact.** With no installed copy, `vendor` staged the committed - artifact of the previous patch as the build source, so a file only the - old patch changed reached the new artifact unnoticed. The committed - artifact is now staged only for the patch that built it; a newer patch - fetches the pristine package per the lockfile (`--offline` skips it). - -- **Ledgers written by a newer socket-patch are never half-reverted.** - A hosted redirect edit kind this release does not understand used to - let `rollback` drop the npm record beside it, leaving that lockfile - redirected with nothing tracking it. Such an edit now holds every - record in the redirect ledger ("the redirect ledger holds a {kind} - edit this socket-patch release does not understand; upgrade - socket-patch"). When it names a purl, that purl's own revert in - `rollback `, `remove` and the hosted-to-vendored takeover - refuses with nothing written, and the takeover's ledger reconcile - leaves the purl for the manual cleanup. When the scope still covers - every hosted record, the whole-ledger replay goes on to unwind the - lockfiles this release understands, but keeps every record and the - unknown edit. - `repair` skips vendored npm entries whose `flavor` it does not know - (`vendor_wiring_unknown_revert_blocked`) instead of rebuilding them - with the wrong layout rules. vlt ledgers (`redirect_vlt_lock_node`, - `flavor: "vlt"`) require the socket-patch release that adds vlt - support. - -- **A patch file the patch never changes no longer blocks vendoring.** The - patch view serves `blobContent` only for the files a patch CHANGES, so a - zero-delta file (`beforeHash == afterHash`) comes back with hashes and no - content — and needs none: the pristine copy already carries the patched - bytes. The vendor stager counted such a view as a failed fetch, which made - any patch carrying a zero-delta file permanently unvendorable (live - example: `pkg:npm/tar-fs@2.1.1`). -- **One unstageable patch no longer kills a whole vendored run.** A package - whose patch content cannot be obtained now gets its own `failed` event - with `errorCode: "no_local_source"` and the rest of the run still vendors, - in `vendor`, `scan`/`get --mode vendored` and `repair` alike. The event's - `error` names the real reason (which file the view served without content, - a malformed blob, or the fetch error) instead of the generic run-level - "patch artifacts unavailable (offline or download failure)". - **JSON consumers:** for a partial staging failure the vendor envelope is - now `status: "partialFailure"` with `error: null` and per-package events, - where it used to be `status: "error"` with a top-level - `error.code: "no_local_source"` and an empty `events[]`. The run-level - shape is unchanged when NOTHING in the manifest can be staged (including - a one-patch manifest) — `no_local_source` can therefore arrive run-level - or event-level, and both shapes are documented in CLI_CONTRACT.md. -- **`get` emits its patch lists in a stable order.** The release-variant - narrowing drained a `HashMap`, so `download.patches`, `apply.patches` and - the per-patch stderr lines came out in bucket order: two identical runs of - the same project emitted the same records in different orders. All of them - are purl-ordered now, matching every sibling collection in the envelope. -- **A requirements.txt this CLI already rewired stays in the lockfile - inventory.** Both shapes we write — the hosted `name @ ` - direct reference and the vendored bare `./.socket/vendor/pypi/…` wheel - path tagged `# socket-patch vendor: ==` — are read back as the - package they replace (discovery-only, exactly like the `==` pin they - replaced). A second hosted run over a wet requirements.txt reported - `packagesWithPatches: 1` instead of 12; a vendored one under-reported the - same way. -- **`vex`'s API-fallback note no longer depends on which refusal landed - first.** When the patch API refuses several patch records, the - `api_auth_fallback` note quoted whichever refusal happened to answer - first — a race, so two runs of the same project could report different - text (`Unauthorized` or `Forbidden`) and retry the refused records in a - different order. Both now follow the order the records are listed in, - like every other note. -- **Hosted Go redirects no longer claim patches that did not land.** - `scan`/`get --mode hosted` counted a Go module as redirected (recorded - it in the redirect ledger, so `vex` attested it) whenever any project - file contained the patch-server origin — e.g. an already hosted - `package-lock.json` — or leftover `patch.socket.dev/gopatch/…` go.sum - lines, even when the go.mod rewrite was refused. A Go module now counts - only when its go.mod `replace` and both go.sum lines are in place. A - module that go.mod does not require and go.sum does not list at the - patched version (another project's module found in the shared module - cache) is refused with `redirect_golang_not_in_module_graph` instead of - getting an inert `replace`. -- **Switching a vendored Go module to hosted mode cleans up the vendored - copy.** `scan`/`get --mode hosted` rewrote the vendored `replace` but - left `.socket/vendor/golang//` and its vendor-ledger entry - behind, so the next `vendor` run switched the module back. The hosted - run now reverts the vendored state first, as it already did for cargo - and npm. -- **Go `replace` directives the CLI did not write are left alone.** A - replace onto another checkout's vendored copy - (`../other/.socket/vendor/golang/…`) or onto a module under - `patch.socket.dev/gopatch/` other than `` was treated as - socket-owned and could be rewritten or removed. Only - `./.socket/vendor/golang/…`, `./.socket/go-patches/…` and exactly - `patch.socket.dev/gopatch/` are now owned. -- **Go replace edits keep go.mod valid and readable.** A go.mod carrying - two socket-owned `replace` lines for one module (for example after a - merge) is collapsed to one instead of leaving a duplicate go rejects; - refreshing a directive keeps its trailing `// comment`; and quoted - module paths (`"github.com/x/y"`) are recognized, so a quoted user - replace is no longer duplicated and a quoted `require` still gets the - version check. -- **`+incompatible` Go modules resolve in vendor and apply.** Purls that - spell the version `v2.0.0%2Bincompatible` are now percent-decoded, so - the module is found in the module cache and the `replace` and copy - directory carry the real `+incompatible` version. -- **`+incompatible` Go copies survive `apply` reconcile.** A manifest key - spelled `%2Bincompatible` no longer makes the freshly applied - `.socket/go-patches/…@v2.0.0+incompatible` copy look orphaned, so it and - its `replace` are kept. -- **Hosted Go rollback restores go.sum byte for byte.** The upstream - module's go.sum lines that the redirect pruned went back at the end of - the file; they now return to the position `go mod tidy` sorts them to - (semver order within a module). CRLF go.mod/go.sum files also unwind - cleanly, with no leftover socket lines or blank lines. -- **Vendoring a hosted Go module unwinds the hosted redirect first.** - `vendor` / `get --mode vendored` over a hosted-redirected Go module left - its redirect-ledger record and the socket module's go.sum lines behind - (with the upstream lines still pruned). Go now takes the same per-purl - takeover revert as cargo and npm (`vendor_takeover_reverted_redirect`), - and scoped `rollback ` / `remove ` of one hosted Go module - works without an unscoped rollback. -- **Vendored Go fetches honor `GOPROXY=off`, `direct` and `GOPRIVATE`.** - With the module missing from the module cache, the pristine fetch fell - back to `https://proxy.golang.org` even when go itself would ask no - proxy, sending private module paths off the machine. It is now refused - (`vendor_fetch_unverifiable`, then the usual `package_not_installed` - skip) unless `SOCKET_GOPROXY` names a proxy. -- **yarn berry projects on Windows (CRLF files) are redirected and vendored - instead of refused.** yarn berry (2.x–4.x) writes a file it creates with - the OS line ending (`os.EOL`) and keeps an existing file's majority ending - on every later write (`normalizeLineEndings` in yarnpkg-fslib's - `FakeFS.ts`, used by `Project.persistLockfile` and - `Workspace.persistManifest`) — so on Windows a fresh `yarn.lock` and the - `package.json` yarn first pretty-prints are CRLF, and a `core.autocrlf` - checkout makes them CRLF on any OS. `scan --mode hosted` / `get --mode - hosted` refused every such lock (`redirect_yarn_berry_crlf_unsupported`, - redirected 0); a CRLF lock is now rewritten in its own line ending — every - untouched byte, a leading BOM included, round-trips — and the ledger records - the lock's on-disk CRLF fragments, so `rollback`, `remove` and the hosted → - vendored takeover restore it byte-for-byte (they also replay a ledger - recorded on a checkout whose uniform line ending has since flipped, LF ↔ - CRLF). `vendor` / `scan --mode vendored` now keep `package.json`'s layout - (BOM, indent, line ending, trailing-newline shape) on both the wiring and - the revert: `vendor --revert` wrote a CRLF manifest back LF, never - byte-identical to the pre-vendor file. A BOM'd `package.json` (and a - BOM'd `.yarnrc.yml`, whose first-line `compressionLevel` was read as - unset) no longer fails the vendored backend, and every berry reader skips - a BOM in front of a header-less `__metadata:`. Verified on real yarn - 4.12.0 (hosted, vendored, workspaces, pnpm linker, both mode takeovers) - with the fixtures re-spelled CRLF, and on yarn 2.4.3 / 3.8.7 (still - refused for their cacheKey, never for their endings). -- **A yarn berry mode takeover no longer strips the old mode's patch before - the new mode refuses the project.** `scan` / `get --mode hosted` over a - vendored berry purl reverted its vendored wiring, ledger entry and - artifact (`redirect_takeover_reverted_vendored`: "now fully hosted") and - only then ran the rewriter, which refused a lock with mixed line endings - (or an unsupported `cacheKey` / `.yarnrc.yml` `compressionLevel`) — - `redirected: 0`, and the next `yarn install` pulled the unpatched registry - package. `vendor` / `scan --mode vendored` over a hosted berry purl did the - same in reverse (`vendor_takeover_reverted_redirect`, then `failed` - `vendor_yarn_berry_mixed_line_endings`). Both takeovers now run the new - mode's berry gates first — wet and `--dry-run` alike — and a refused purl - keeps the old mode's wiring byte-identical. -- **Two vendored versions of one cargo crate are documented — and now - warned about — as needing cargo 1.45.** The docs said older cargo (1.41) - only needed a populated crates.io index. It needs more than that: cargo - before 1.45 resolves every source-less `Cargo.lock` entry for a crate - through ONE `[patch.crates-io]` path — the entry whose KEY sorts last — - so one of the two versions is pinned to the other's copy and `cargo build - --locked` fails closed with ``patch for `` … did not resolve to - any crates``, index or no index. The old-toolchain e2e passed only - because its fixture uuids happened to sort the other way; it now uses the - adversarial order, and the floor was measured rather than assumed — on - one two-version fixture in both key orders, 1.41.1, 1.42, 1.43 and 1.44 - refuse the adversarial order while 1.45, 1.49, 1.53, 1.56 and current - stable resolve either order, each lock entry to its own copy. Vendoring a - second version of a crate warns with `cargo_multi_version_old_cargo` - unless the project's `rust-version` or `rust-toolchain[.toml]` promises - cargo 1.45 or newer (socket-patch never runs `cargo`, so those files are - the only signal it has). A SINGLE vendored version still builds on cargo - 1.41, as before. -- **A CRLF `Cargo.lock` stays CRLF, and reverts byte-for-byte.** Vendoring - rewrote every line of a lock committed with Windows line endings as LF - (`toml_edit` renders LF only), and `vendor --revert` then "restored" the - all-LF file — a whole-file diff on a Windows checkout and a rollback that - was not byte-identical. The lock edits (detach, retag, restore) now map - the rendering back onto the file's own line endings, the way the copy's - `Cargo.toml` already did, in lock formats v1–v4: a CRLF lock stays CRLF, - a missing trailing newline stays missing, and every line a mixed-ending - lock's edit leaves alone keeps its own ending. -- **Vendored mode can patch a package whose version carries build - metadata.** The patches API serves canonical PURLs, so a semver build - metadata version arrives percent-encoded - (`pkg:cargo/wasi@0.11.0%2Bwasi-snapshot-preview1`). The PURL parsers - compared that raw spelling against the lockfile / install directory's - `0.11.0+wasi-snapshot-preview1`, never matched, and refused the package - (`vendor_fetched_missing`, then `locked_version_mismatch`) — so no cargo - crate with build metadata (`wasi` is in most Rust dependency graphs) - could be vendored at all. Every ecosystem's PURL parse now - percent-decodes the namespace, name and version once, after the - `/`-and-`@` split and before the path-safety guards, so an escaped - separator still cannot introduce a path segment. Hosted mode was already - correct. -- **A vendoring-service outage no longer re-vendors packages.** An npm - re-run (every lock flavor, `bun.lockb` included) re-acquired its tarball - from whichever source answered — the service's prebuilt, or a local pack - with different bytes — so an outage or its recovery rewrote the lock's - integrity and the committed tarball and reported `applied`. A re-run now - keeps the committed artifact whenever the vendor ledger vouches for it - (uuid-bound path, no symlink, sha256 + size equal to the ledger, a - canonical archive an installer extracts exactly as decoded, every - patched file verified from the same bytes) and is `already_vendored` - with no service request, in every `--vendor-source` mode (including - `service` + `--offline`, as cargo and composer already did; golang now - matches). A pypi re-scan after a relock re-wires the committed wheel - instead of pinning a new sha, the PDM partial-relock guard holds - whichever source built the wheel, a wiring failure no longer deletes a - committed wheel, and a missing prebuilt wheel during an outage now says - to wait for the service. `--dry-run` previews the same reuse, so it no - longer predicts a `service` + `--offline` refusal the real run does not - have. Transient service failures (network, timeouts, 429, 5xx) are - retried with backoff, each attempt is time-bounded, and after two - consecutive exhausted fetches the run stops calling the service. -- **Terminal output is clean on every command.** Progress lines no longer - leave stale text behind (`scan` printed e.g. `Found 7 patches for 1 - packagesatch 7/7)`) or run into warnings printed while they are active. - Progress, prompts, color and truncation now share one implementation. - - **Progress lines:** a status line clears itself on finish. It is never - drawn off a TTY, under `TERM=dumb`, in debug mode, or under - `--json`/`--silent`. `fetch`, `vendor`, lock waits and - `--update` checks now show progress instead of going quiet. - - **Prompts:** Ctrl-D at a `[Y/n]` prompt now declines instead of - accepting. Keys pressed while a command is working no longer answer - the prompt that follows (`get`, `rollback`). The cursor is restored when a selection menu is - interrupted. - - **Color:** `NO_COLOR`, `CLICOLOR`, `CLICOLOR_FORCE` and `TERM=dumb` are - honored. Colored table rows now align. - - **Wording:** counted nouns read `1 package` / `2 packages` instead of - `package(s)`. `Error:` / `Warning:` prefixes are consistent, and - warnings go to stderr. `--silent` is errors-only, but a failing run - still prints why. Output that came out in random order is now sorted. - `--help` pages no longer show developer notes. - - **Behavior fixes:** `get --dry-run` and `vex --dry-run` no longer write - anything, and `vex -O -` writes to stdout. `scan --json` never stops at - an interactive menu. API errors show the server's message instead of a - raw JSON body. -- **Reversal leaves no `.socket/` residue.** `rollback`, `remove`, - `vendor --revert`, the hosted unwind and the GC sweeps now prune what they - empty: an emptied redirect or vendor ledger is deleted together with the - empty `.socket/vendor//` and `.socket/vendor/` directories (per-entry - vendored reverts prune their ecosystem husk; a `redirect-state.json.corrupt` - quarantine keeps its directory), emptied `blobs/`, `diffs/` and `packages/` - stores are removed, and `.socket/` itself goes with the lock when nothing is - left — so a fully unwound hosted or vendored project has no `.socket/` at - all. Deliberately kept: the zero-patch `.socket/manifest.json` - (`{"patches": {}}` — `list`/`apply`/`vex` exit codes depend on it). -- **`scan --prune` says what it skipped and what it could not finish.** The - `gc` JSON sub-object gains `failedVendoredEntries` plus the additive - `skipped: {code, message}` (`lock_held` | `lock_io`) and - `warnings: [{code, detail}]` (`vendor_state_write_failed`, - `manifest_write_failed`, `cleanup_failed`) keys, with matching `GC: …` - human lines, so a pass that could not take the lock or could not rewrite a - ledger no longer reads as a clean all-zero sweep — and a lock I/O fault or - a failed rewrite is never mislabelled as lock contention. A legacy manifest - record migrated into the vendor ledger is reported as the - `vendor_manifest_record_migrated` / `vendor_manifest_migration_failed` run - warnings; a corrupt manifest no longer fails a vendored run (standalone - `vendor` still fails closed on it). -- **Vendored `get`/`scan` name the patch they replace.** A `downloaded` - record for a purl the vendor ledger holds at another uuid carries `oldUuid` - and the human `[fetch]` line reads `(replacing )`; - `get --mode vendored --dry-run` prints `[dry-run] Would download and vendor - N patches. No changes made.` on both identifier paths; the `[note]` and - `Patch record saved to` lines are gone with the manifest. -- **Agent-mode `get` leaves nothing behind when it records nothing.** - `.socket/` and `.socket/blobs/` are created only when a record is - persisted (all-skipped and all-failed runs leave no `.socket/`), a - same-uuid `get ` re-run rewrites neither the manifest nor the blobs, - and a blob/diff fetch that lands nothing creates no `.socket/blobs/` or - `diffs/` — the `Cannot create blobs/archives directory` all-failed envelope - is gone; an uncreatable cache dir is a per-entry - `Failed to write blob/archive to disk`. -- **`ownership_not_restored` is a warning, not silence.** A file `apply` - patched (or `rollback` restored) whose ownership could not be put back to - the original uid/gid now surfaces as an `ownership_not_restored` run - warning (`warnings[]` plus `Warning (ownership_not_restored): …` on - stderr) instead of riding a successful result unseen; the mode is still - restored. -- **`remove` on ledger-only state.** A missing manifest beside a vendor or - redirect ledger that holds nothing for the identifier answers `not_found` - (exit 1) instead of `manifest_not_found`; a second `--skip-rollback` on - the ledger-only leftover of an earlier `--skip-rollback` is refused with - `vendor_state_retained` (was `not_found`); every matching vendor-ledger - entry — detached or not — is removable through the ledger with - `--preserve-state` and drift-keeps honored exactly as on the manifest - path; manifest entries are removed in sorted order, and the - `(not installed)` line prints only when something was not installed. - `rollback` prints `No patches found in manifest` only for an unscoped run - with no work in any leg. -- **A corrupt vendor ledger is reported, never swallowed.** `vex` refuses - it outright (`vendor_ledger_corrupt`, see Changed); `list` degrades it to - a `Warning: unreadable vendor ledger …` line (muted by `--silent`) rather - than an error. -- **`repair`/`vendor` state hygiene.** `repair` resolves installed copies - through qualified ledger keys (gem `?platform=`, pypi `?artifact_id=`, - maven `?classifier=` no longer read as "not installed"), puts a crashed - rebuild's `.pre-rebuild` set-aside back when it is the only copy, - and reports an absent or empty blobs dir as `No blobs to clean up.`; every - artifact sweep (`repair`, `rollback`, `remove`, `scan --prune`) keeps going - past one unremovable file and reports the failures afterwards; `vendor`'s - dropped-record reconcile saves per purl and counts a failed save as - `vendor_state_write_failed`; `vendor_marker_write_failed` is the one - marker-failure warning for every backend (cargo/golang/pypi's - `marker_write_failed` retired), and a pypi vendor whose informational - marker cannot be written now succeeds with that warning instead of - sweeping the wheel; npm, yarn (classic and berry) and pnpm reverts honor - the drift-keep on an unwired entry like bun and legacy pnpm already did; - the hosted replay no longer credits a byte-identical hatch rewrite as an - edited file; a corrupt redirect ledger met by a hosted scan is reported - once, not twice. -- **Manifest inputs are validated before they become paths.** `apply` - refuses an `afterHash` that is not a 64-hex blob hash or a uuid that is not - a plain path segment and reads blobs through a symlink-refusing opener (a - poisoned manifest or a planted `blobs/` symlink can no longer read out of - tree); `rollback` deletes patch-added files in every pnpm store copy and - heals a patched twin of an already-original primary. -- **Human chrome.** The global-mode `Using at: ` banner moves to - stderr so piped stdout stays clean; the empty-crawl hint of `scan` and - `get` reads `Run your package manager's install first.` instead of a fixed - npm/yarn/pnpm/pip/cargo/go/mvn/composer list; `vendor --revert` and the no-manifest - no-ops of `vendor` and `apply` (and `apply --check`) build no API client, - so the `SOCKET_API_TOKEN` advisories no longer print on hooked - manifest-less runs, and `repair` prints its token notice once. -- **Telemetry and self-update robustness.** The telemetry client uses a 2 s - connect timeout (a blackholed endpoint no longer stalls every command for - the full request budget), and `--update` maps only a contention errno to - `update_in_progress` — other lock failures surface their real cause. -- **A scan that writes nothing never creates `.socket/`.** Report-only, `--dry-run`, - zero-discovery and no-op runs (hosted or otherwise) no longer scaffold the - directory or a lock file; a GC pass checks for a manifest before it locks. -- **`apply --silent` on an all-unmatched manifest prints its error line** — - errors are never muted by `--silent`; and the no-manifest early exits of - `apply` and `vendor` name the missing `.socket/manifest.json` instead of - "No .socket folder found" (the folder may legitimately hold vendored - state). -- **Hosted redirect hygiene.** Missing project files no longer skip silently: - `redirect_composer_no_lockfile`, `redirect_gem_no_gemfile` (neither manifest - nor lock present) and `redirect_maven_no_pom` (no `pom.xml`, no Gradle - build) warn once per run; a present-but-corrupt `packages.lock.json` warns - `redirect_nuget_lock_unparseable` before any config mutation; a `Cargo.lock` - with several same-name+version `[[package]]` blocks and no `source` - disambiguation warns `redirect_cargo_lock_pkg_ambiguous` and skips - transactionally; a registry override of the wrong kind now warns the arm's - missing-override code for nuget/gem/golang (previously a silent skip); the - ledger's `redirect_nuget_source` edit records `action: "added"` when - `nuget.config` was authored from scratch; hosted-revert lockfile restores are - atomic and mode-preserving (including `bun.lockb`), and a FIFO or symlink - squatting on a lockfile is refused instead of wedging the revert. -- **Vendor backend parity.** Gem reverts follow every other backend's - drift-keep rule (genuine drift keeps artifact + ledger entry; converged files - are silent; a missing `Gemfile`/`Gemfile.lock` warns `vendor_lockfile_missing` - and still removes the artifact); composer, maven and nuget reverts keep the - artifact + ledger entry (`kept_artifact`, the `vendor_revert_kept` skip) - while the live `composer.lock` / `pom.xml` / `nuget.config` still names the - drift-skipped entry's uuid dir — previously the dir was deleted under a - `` / `` that still routed at it — and remove it once - nothing references it; the golang service leg stages its download - and, when a re-download of a wired present copy fails, keeps the copy and - directive instead of tearing them down; poetry/pipenv/requirements refuse - symlinked targets (`pypi_{poetry,pipenv,requirements}_symlink_unsupported`) - and every pypi flavor refuses a project file that changed between plan and - write (`pypi_{poetry,pdm,pipenv,uv}_changed`) instead of clobbering it; - an - unreadable (EACCES / squatting directory or FIFO) redirect ledger is - reported as unreadable and left in place instead of being quarantined as - "malformed"; a blob-cleanup pass keeps sweeping after one unremovable file - and reports the first error afterwards; the ledgers skip byte-identical - rewrites. -- **Hosted composer redirects no longer fall back to the pristine git - source.** Composer 1 and 2.2 LTS silently install the upstream commit from - `source` when the hosted dist fails; the rewriter now drops the entry's - adjacent `source` block (one fragment edit, reverted byte-for-byte) and - warns `redirect_composer_source_kept` when a hand-ordered source cannot be - dropped. -- **Hosted gem locks keep bundler's source order.** The patch-registry - `GEM` section is inserted where bundler sorts it, so `BUNDLE_FROZEN=true - bundle install` on bundler ≥ 4.0.19 no longer refuses the converged lock. -- **v1 `Cargo.lock` files redirect and vendor correctly.** Hosted and - vendored rewrites now follow the `[metadata]` checksum table and rewrite - dependents' full-id references, so `cargo --locked` accepts the lock (and - the revert stays byte-identical). -- **Hosted cargo pins every declaration of the patched version.** Each - version of a multi-version crate is pinned only in the declarations whose - requirement selects it (a requirement matching several locked versions is - refused `redirect_cargo_toml_dep_unrewritable`), and workspace-member and - in-root path-dependency manifests are pinned beside the root, so - `cargo --locked` accepts the redirected lock. Member discovery never - follows a symbolic link, so nothing outside the project is rewritten. -- **Hosted cargo refuses crates a pin cannot reach.** A crate another - `Cargo.lock` package also depends on (a crates.io or git crate, or a path - package outside the project) now warns - `redirect_cargo_transitive_dependents` and is skipped instead of being - reported redirected while that package compiled the unpatched copy; a - transitive-only crate's `redirect_cargo_toml_dep_not_found` detail now - says so and points to `--mode vendored`. A crate declared only with - requirements the patched version does not satisfy (cargo resolves those - declarations to another version) is refused - `redirect_cargo_toml_dep_unrewritable`, the Socket backend's code for the - same shape, instead of `redirect_cargo_toml_dep_not_found`. A project with - NO `Cargo.lock` has no resolved graph to ask, so a crate declared beside - any other dependency — anything but a path dependency on a manifest the - same run pins — or beside a workspace member this run did not read (a - glob, a member outside the project or behind a symbolic link) is refused - `redirect_cargo_lockless_dependents` (commit a lockfile, or use `--mode - vendored`); a project whose only dependency is the patched crate has - nothing that could pull it in and still redirects. -- **CRLF cargo projects redirect in hosted mode.** All-CRLF `Cargo.toml`, - `Cargo.lock` and cargo configs are rewritten with their endings kept - (they were refused), and `remove` / rollback still find the recorded - edits after a checkout converts the line endings. -- **Hosted cargo `remove` restores every byte, in any order.** An appended - registry block leaves the user's config exactly as it was (trailing blank - lines or a missing final newline included) and a created config is - deleted with the last block; v1-lock and multi-version patches, ledgers - written by older CLIs included, can be removed in any order; and a crate - declared with the same line in two sections gets both pins reverted. -- **yarn 4.0.x checksums keep the lock's own spelling.** Vendored and hosted - berry rewrites write bare-hex `cacheKey: 10c0` checksums when the lock - does, so `yarn install --immutable` no longer fails with YN0028. -- **npm 12 dual-lock projects vendor both locks.** `vendor` rewires a - `package-lock.json` npm 12 keeps beside a committed shrinkwrap (else warns - `vendor_npm_sibling_lock_unwired`), and hosted runs warn - `redirect_npm_allow_remote` (npm 12's `allow-remote=none` refuses - redirected tarballs unless `.npmrc` sets `allow-remote=all` — which hosted - mode now writes itself, see Added) and `redirect_npm_legacy_client` (npm 6 - ignores a v1 lock's `resolved`). - -- **Bun refusal safety:** hosted compatibility is checked before removing - an existing vendored patch, including during dry-run. Vendored preflight - exemptions require live local lock tuples; a ledger retained by - `rollback --preserve-state` cannot bypass a refusal or hide it in a preview. - Symlinked `bun.lockb` files are refused before patching so their links - survive, and `vendor --silent` keeps refusal diagnostics on stderr. - -- **Bun projects: every text-lock generation is accepted, vendored refusals - fire before any write, and every mode change unwinds.** `bun.lock` - `lockfileVersion` 0 — the opt-in text lock Bun 1.1.39–1.1.45 write with - `--save-text-lockfile` — joins 1 and 2 in the shared version gate, so hosted - mode redirects it (golden fixture `npm/bun/lock-v0`), vendored mode wires it - and the lockfile inventory discovers it; a newer version is now refused with - "update socket-patch" instead of a re-lock that would reproduce it. Workspace - locks are refused only where Bun cannot consume the rewrite: hosted mode - refuses a version-0 lock holding `workspace:` packages - (`redirect_bun_workspace_unsupported`; delete `bun.lock` and re-lock with - Bun ≥ 1.2, which writes version 1 — accepted; a plain in-place - `bun install` bumps the version only when a workspace depends on another - workspace, otherwise Bun 1.2.0 keeps version 0 and 1.2.23+ fail to - resolve) and vendored mode refuses any pre-version-2 workspace lock before - writing (`vendor_bun_workspace_unsupported` — Bun 1.2–1.3 resolve a - workspace member's local tarball path relative to the member; delete - `bun.lock` and re-lock with Bun ≥ 1.4, since an in-place `bun install` - keeps the existing version, or — for a version-1 lock — use hosted mode; a - version-0 lock is told to re-lock with Bun ≥ 1.2 first, since hosted - refuses it too), while purls already vendored (by the ledger at the - selected uuid, or with every matching lock tuple already pointing into - `.socket/vendor/`, so a superseding patch uuid re-pins in place), re-runs - and `repair` on such a lock keep working; a corrupt - `.socket/vendor/state.json` met by that preflight is reported as - `vendor_state_unreadable` rather than a Bun lock code. `scan --mode vendored`, - `get --mode vendored` (search and uuid paths) now - preflight the Bun lock BEFORE any download: a malformed binary, unreadable, - unsupported-version or pre-version-2 workspace lock marks the npm patches - `failed` with the vendor refusal code and detail, fetches nothing and - records no patch — the `scan` / `get ` path writes nothing under - `.socket/` and exits `partial_failure`, `get --mode - vendored` exits 1 with `status: "error"` and writes nothing — where - previously the record landed in the manifest and the vendor step failed - afterwards (and a detached run over an alias install misreported - `package_not_installed`). The refusals stay visible under `--silent` - (code-tagged stderr line), `--dry-run` previews them as the additive - `would_refuse` action (the human `scan` and `get` previews both print the - `[would-refuse]` lines). Valid binary locks are inventoried and patched - directly without a Bun runtime; malformed binary locks report - `bun_lockb_invalid`, `redirect_bun_lockb_invalid`, or - `vendor_bun_lockb_invalid` at the corresponding entry point. Hosted → vendored - takeover now works for bun — - `scan`/`get --mode vendored` and `vendor` over a hosted-redirected `bun.lock` - claim and replay that purl's hosted edit instead of refusing - `redirect_revert_failed`, and `vendor --dry-run` probes the takeover instead - of promising it — as do `rollback ` / `remove ` of one of - several hosted bun records; on a lock the vendored backend refuses (a - pre-version-2 workspace lock) `vendor` and its dry run report the refusal - BEFORE the hosted revert, leaving the purl hosted-patched instead of - un-hosting it and then refusing. Native `bun.lockb` edits preserve the - dependency graph and unrelated package metadata while updating binary - pointers, tarball integrity, and the package metadata hash. The hosted text - rewrite keeps CRLF on the rewritten `bun.lock` line. Real-Bun - coverage now runs in CI: the hermetic hosted and vendored suites on Linux, - macOS and Windows (Bun 1.4.2, plus 1.1.45 and 1.2.23 lock-era legs), and - the production native matrix — 16 releases from 0.8.1 to 1.4.2 in hosted - and vendored mode — on pull requests and `main` (rows - carry `cliRevision` and `cliBuildSha` provenance), with - the corrected digest boundary (Bun verifies URL/local tarball sha512 from - 1.3.10, not 1.3.14). Bun 1.1.39–1.3.9 also re-save a hosted URL or - vendored local-tarball tuple WITHOUT its `sha512` on any later lock - re-save (`bun add`, `bun install` after a manifest change); that - digest-less 2-tuple is now recognised as the CLI's own wiring — repeat runs - heal the digest, `repair` rebuilds through it, and `rollback`, scoped - `rollback` / `remove`, `vendor --revert` and both mode takeovers unwind it - to the registry line — where previously every re-save on those releases - left `redirect_bun_entry_not_found` beside `redirected: 1`, a - `partial_failure` rollback and `vendor_lock_entry_not_found` / - `vendor_lock_entry_drifted` refusals. See - `docs/testing/bun-compatibility.md` and `scripts/backtest-bun.py`. (#245) -- **Rollback after a Pipenv relock no longer refuses forever.** `pipenv lock` - (and `update`, and `install ` before 2024) regenerates a redirected - or vendored entry to registry shape on every Pipenv major; that is now the - desired end state — the hosted edit retires and the vendored record is - dropped (`vendor_lock_entry_relocked`) — instead of a permanent drift - refusal that held every pypi revert and kept the orphaned wheel dir. A - foreign `file`/`path` reference is still drift. -- **Same-run `--vex` attests lock-only pypi redirects.** The confirmed purl is - unqualified while the ledger records the API's artifact-qualified purl; - both sides now match on the qualifier-stripped purl, so a lock-only Pipenv - (or uv) checkout no longer exits 1 `no_applicable_patches` after - redirecting its lock. -- **The Pipenv installer probe runs only when a patch targets the lock**, warns - only when the lock was actually rewritten, resolves `pipenv` on absolute - `PATH` entries only (a relative entry would have executed a `pipenv` planted - in the scanned repository), finds `.bat`/`.cmd` shims on Windows, and takes - only the token after `version` (never a stray `Python 3.12` banner). -- Hosted Python redirects now warn when installed files still contain upstream - or modified bytes and omit those packages from same-run VEX. The read-only - probe covers Poetry virtualenvs, repeats on re-scans, and uses persisted patch - records if fetching fresh records fails. - -- **Agent mode finds Poetry's out-of-tree virtualenv.** Poetry keeps a - project's virtualenv under `{cache-dir}/virtualenvs/--py` - by default, so after a plain `poetry install` the crawler saw no - `VIRTUAL_ENV` / `.venv` / `venv` and fell through to the global interpreter: - `scan --mode agent` patched nothing for the project's dependencies (or the - wrong interpreter) while reporting success, and a bare `rollback` pruned the - manifest while the venv stayed patched. The crawler now reproduces Poetry's - own placement — `virtualenvs.create` / `in-project` / `path` and `cache-dir` - from `POETRY_*`, the project's `poetry.toml` and the user `config.toml`, the - platform default cache dir, and Poetry's env-name hash — without running - Poetry, and scans every `-py` sibling. `poetry run socket-patch …` and - `VIRTUAL_ENV` keep working as before. -- **`scan --mode vendored` works from a lock-only Poetry checkout.** The - `poetry.lock` inventory was discovery-only, so a fresh clone with nothing - installed was skipped with `vendor_fetch_unverifiable` even though the lock - records the wheel's sha256 (uv's lock vendored fine in the same scenario). - The inventory now carries the pure-Python wheel's sha256 from `files` (lock - 2.x) or `[metadata.files]` (lock 1.0/1.1), and the pypi fetcher resolves a - hash-only entry through PyPI's JSON API by that digest (verified again after - download; `SOCKET_PYPI_JSON_API` overrides the endpoint). Poetry 0.12's bare - `[metadata.hashes]` names no wheel and still needs an installed copy. -- **`remove` no longer drops the manifest entry of a drift-kept vendored - purl.** When the vendored revert keeps the artifact (`kept_artifact` — - the lockfile drifted), the manifest entry is now kept too - (`skipped`/`vendor_revert_kept`), matching the core RevertOutcome - contract; previously the entry was deleted, stranding a live ledger - entry with no backing record. An all-kept run exits 1 `partialFailure` - with `summary.removed: 0` (never `not_found` — the identifier matched). -- **Rebuilding a missing gem, maven or nuget vendored artifact now updates - the ledger.** When `vendor` / `scan --vendor` found a wired project whose - committed artifact was missing or broken, it rebuilt the artifact but kept - the old fingerprint in `.socket/vendor/state.json` (the gem file - inventory, the maven/nuget `sha256`, and the nuget `packages.lock.json` - pin). If the rebuild came from the other source (the patch service instead - of a local build, or the reverse), the new bytes no longer matched the - ledger. VEX and verification then reported the artifact as tampered, - `repair` could fail, and `vendor --revert` left `packages.lock.json` - pinned to the patched `contentHash`. A rebuild from the patch service was - also reported as `already_vendored` instead of `applied`. The rebuild now - records the new fingerprint and keeps the entry's original wiring records, - so revert still restores the pre-vendor files. If `state.json` has no - entry for the package, or only an entry from another patch uuid, the - rebuild still runs but the ledger is left as it is, because the run has no - pre-vendor originals to record. -- **A prebuilt maven `.jar`, nuget `.nupkg`, pypi wheel or npm tarball from - the patch service must now contain the patched files.** Checking its integrity hash only showed that - the download was intact, not that the archive carried the patch. The - archive was still written as-is and every file was reported as already - patched, so an unpatched archive could be committed and then rebuilt on - every run. Each patched file inside the archive is now checked against the - patch's expected hash before the archive is used. On a mismatch, `auto` - builds the archive locally and warns `vendor_prebuilt_layout_mismatch`, - and `--vendor-source=service` refuses with `vendor_prebuilt_required` (npm - fails the package with the detail). -- **A prebuilt artifact that fails its integrity check is always refused.** - Under the default `--vendor-source=auto`, npm, pypi, golang, composer and - gem (both the `.gem` and its stub gemspec) printed a warning and built the - package locally when the downloaded bytes did not match the integrity the - patch service reported. Bytes that fail verification may have been - tampered with, so these ecosystems now refuse the package in every mode, - as cargo, maven and nuget already did. The refusal code is - `vendor_prebuilt_integrity_mismatch` (npm fails the package with the - integrity detail). Under `--vendor-source=service`, golang, composer, gem - and pypi now report `vendor_prebuilt_integrity_mismatch` instead of - `vendor_prebuilt_required`. -- **`service` vendor source without an API client is refused.** This affects - `socket-patch-core` callers that pass a `VendorServiceConfig` with - `source: Service` and no `client` (the CLI always configures a client). - Every backend used to build the artifact locally in that case, even though - `service` promises that only the patch service's artifact is used. They now - refuse with `vendor_prebuilt_required` before doing any work, the same way - `--offline` is already refused. -- **Rebuilding a missing cargo vendored copy now honours - `--vendor-source`.** When a wired project's committed crate copy was - missing or stale, `vendor` always rebuilt it locally from the installed - source. Under `--vendor-source=service` it did so even with `--offline` - or without an API client, and reported success. The rebuild now uses the - patch service's prebuilt crate like a fresh vendor does, so `service` - mode refuses (`vendor_service_offline_conflict` / `vendor_prebuilt_required`) - when the service cannot be used, and `auto` still builds locally when it - has no prebuilt crate. - -### Changed - -- **`scan` keeps a patch you already have unless the new one supersedes - it.** A package whose recorded patch (agent manifest, hosted lockfile - pin or vendor ledger) still ranks level with the top offer on every - meaningful rung (merged state, severity, a later publish date) keeps - its recorded patch instead of switching on the tier or uuid tiebreak, - so re-running `scan` never swaps patches. `updates[]` and the - `[UPDATE]` marker now use the per-package records the selection itself - uses, so they list exactly the upgrades the run applies; a JSON - report-only run still reads the batch records. -- **Fewer downloads in vendored runs.** A vendored run now asks the patch - service for all of its planned packages' download references in one - request (in chunks of 500) from the first package it reaches, in place - of one request per package; an outage costs the same retries as before, - and a package the service reports still building is asked again at its - turn. A pypi patch the service serves as an sdist (every patch without a - file qualifier) is refused from its reference, before its bytes are - downloaded: `auto` still warns `vendor_prebuilt_unavailable` and builds - the wheel locally, `service` still refuses. -- **One owner rule for the patch stores.** `list`, `vex`, `scan`'s - `updates[]`, `rollback` and `remove` now read the - manifest and the vendor ledger (plus, in `vex`, the hosted records) - through one view (`socket_patch_core::ledgers`) with one precedence: - manifest, then vendor ledger, then hosted records, by ledger key; a - manifest key claims every vendor entry filed under it or naming it as - base purl. Visible differences: `scan`'s `updates[]` no longer folds a - vendor entry the manifest claims by base purl; `vex` treats every vendor - entry a manifest key claims as a fallback copy of that key's record (a - second variant of the same base purl used to become its own candidate). - `get`'s installed-version narrowing now uses - `scan`'s lockfile and vendored-ledger discovery, so a corrupt vendor - ledger falls back to the committed artifacts there too. -- **The npm crawl skips tagged cache directories.** The walk that finds - workspace `node_modules` trees no longer descends into a directory that - carries a [Cache Directory Tagging](https://bford.info/cachedir/) - `CACHEDIR.TAG` beginning with the standard signature (every cargo - `target/` does), using the directory listing it already reads. One - semantic change: a `node_modules` inside such a directory, or anywhere - below it, is no longer crawled, so its packages are no longer scanned, - patched or attested. Every command that looks for installed npm copies - walks the same trees, so the change reaches past `scan`: `scan --prune` / - `--sync` treat a package installed only under a tagged directory as not - installed and garbage-collect its manifest entry and blobs (unless a - lockfile still resolves it), and `apply`, `rollback`, `remove`, `repair`, - `vendor` and `vex` no longer find copies there — so `remove` leaves such a - copy's patched files in place. The scan root itself is always crawled, and a - `CACHEDIR.TAG` without the signature (or that is a directory or a - symlink) prunes nothing. On a Rust-plus-JS monorepo this skipped 57% of - the walked directories. See docs/ecosystems.md. - -- **`scan` sends up to 32 patch-API requests at once on the authenticated - API, up from 8.** Each step sizes its window from the requests it has to - make: a quarter of them, between 8 and 32 — the batch queries, the - per-package patch lists, the hosted and vendored record views, discovery's - baseline views and `get`'s views. A step with 32 or fewer requests still - runs 8 at once; one with 128 or more runs 32. The fixed-size windows - follow the new cap up to their own ceilings: `vex` / `scan --vex` record - fetches now run up to 10 at once (was 8), wheel metadata stays at 4 and the - vendored archive prefetch at 4. The public proxy stays at 4. - `SOCKET_API_CONCURRENCY=` still overrides the adaptive cap (1-32; on - the proxy it can only lower it); the fixed windows keep their own ceilings - on top of it. Output is unchanged — every window folds its - answers in request order — but a large monorepo's hosted scan at 100 ms of - latency drops from ~20 s to ~9 s. - -- **`scan` queries the authenticated API 500 packages per batch, up from - 100.** Unset, `--batch-size` / `SOCKET_BATCH_SIZE` now follows the - endpoint: 500 purls per `POST /v0/orgs/{org}/patches/batch` (the server's - own per-request maximum) and 100 per `POST {proxy}/patch/batch` on the - public proxy, as before. A given size still applies as-is on either - endpoint. A batch whose JSON body would pass 256 KiB (the public proxy's - body cap) is now split, deterministically, into consecutive smaller - batches; at the default sizes that takes purls averaging over ~500 bytes. - A run downgraded to the proxy mid-run keeps its chunks, so it can send - the proxy batches of up to 500 purls (within the proxy's 256 KiB cap and - its upstream's 500-purl limit). Output is unchanged; the request count - and shape change — a large monorepo sends 30 batch requests instead of - 147 (depscan: 12 instead of 56), and `api_batch_failed` warnings number - the larger batches (`API batch 2 of 12 failed: …`). - -- **The crawl's directory walks run on 4 threads by default.** The walk - pool behind the `node_modules` walk and the Maven repository walk (and its - POM parse) used one thread per logical CPU (up to 16), but the walk is - bound by the kernel's directory cache: on a 14-core Mac and on Linux - ext4, 4 threads walked a large monorepo's `node_modules` as fast as or - faster than one per CPU, with a quarter of the system time (see - `walk_pool.rs` for the measurements; the Maven walk shares the pool and was - not measured separately). The default is now 4, or the performance-core - count when that is lower (`hw.perflevel0.logicalcpu` on Apple silicon). - `SOCKET_WALK_THREADS=` overrides it, clamped to 1-16 and to the CPU - count. What the crawl finds, and its order, are unchanged. - -- **Maven discovery takes coordinates from the `~/.m2` path.** A POM at its - canonical `///-.pom` - location is no longer opened: its groupId / artifactId / version come from - the directory names, which is where Maven itself writes every POM, so the - crawl skips reading and parsing tens of thousands of files. The path only - spells the right group when the scan root is the repository root, so each - top-level group directory (`org/`, `com/`, ...) is confirmed first: the - first canonical POM under it whose contents parse must agree with its - path, and a directory whose first such POM disagrees — every one of them - when `--global-prefix` / `SOCKET_GLOBAL_PREFIX` / `MAVEN_REPO_LOCAL` points - one level above or inside the repository — is read content-first exactly - as before. Other `.pom` files (timestamped SNAPSHOT POMs, hand-placed - extras, a dotted group directory) are parsed as before. One semantic - change: under a confirmed directory, a POM at a canonical path whose - contents disagree with its directory (hand-placed, or a legacy upstream - POM with mismatched coordinates) now reports the directory's coordinates - instead of the ones in the file. -- **`scan --ecosystems` crawls only the named ecosystems.** Without - `--prune`/`--sync`, a `scan -e npm` no longer walks `~/.m2`, the cargo - registry, the Go module cache and the rest only to filter their packages - away. What the run counts, queries and shows is unchanged - (`scannedPackages` already counted only the selected ecosystems), with - one exception: `lockfileOnlyPackages` and the human "not yet installed" - note now count only the selected ecosystems' lockfile-only entries - instead of every ecosystem's. A GC run (`--prune`/`--sync`) still crawls - every ecosystem — the prune needs the full installed set — and reports - exactly what it did before. - -- **An already-vendored project re-runs `vendor` without the network.** A - vendorable purl with no installed copy (the fresh-clone case) used to have - its pristine artifact downloaded and verified before the backend was even - asked, although the backend's in-sync check answers from the committed - artifact alone. That download is now deferred to the backend branch that - actually reads the pristine tree, whenever the vendor ledger already - covers the purl (its entry records the record's patch uuid and the - committed artifact is on disk — a file artifact such as a wheel or - tarball only while it still hashes to the ledger's `sha256`; `--force` - keeps the eager fetch), and for every lockfile-only npm, cargo, golang - or composer package the registry would fetch and verify (a lock entry - with an integrity, or the pre-vendor resolution the ledger recovers, - that none of its fetcher's pre-download refusals applies to) while the - patch service is enabled (those backends read the pristine source only - once the service falls back to the local build; pypi and gem keep the - eager fetch, which their installed-variant probe reads). A git, path, - local-tarball or custom-registry package is never deferred: it keeps the - eager ladder's `vendor_fetch_unverifiable` + `package_not_installed` - refusal and is not vendored from the service's registry build, and a committed - file artifact that no longer matches its pin keeps the eager ladder's - outcome too. Visible effects: an idempotent re-run - makes no registry requests and no longer reports `vendor_fetched_missing` - for fetches it never needed; with no network (or under `--offline`) the - re-run of an already-vendored pypi, cargo, go or lockfile-only gem - project now SUCCEEDS (`already_vendored`, exit 0) instead of failing - `vendor_fetch_failed` / `package_not_installed`; an npm, cargo, golang or - composer package the service serves is never downloaded from the - registry. When a deferred fetch does - happen (a drifted committed copy being rebuilt locally, a service miss), - its `vendor_fetched_missing` warning is recorded just ahead of that - package's own event instead of in the up-front fetch pass, and a failed, - unverifiable or `--offline`-refused deferred fetch reports exactly the - eager ladder's outcome for the purl (`vendor_fetch_failed` / - `vendor_fetch_unverifiable` + `package_not_installed` / - `package_not_installed`), in loop order. `vendor --vendor-source build` - (or no service config) now refuses a not-installed gem that the lock can - verify and no ledger entry covers with `gem_spec_missing` BEFORE - downloading it: a local build can never vendor a downloaded `.gem` (no - eval-able stub gemspec), so the download was pure waste. The refusal - keeps the backend's detail text and drops the `vendor_fetched_missing` - warning that used to precede it; since it now comes first, a gem the - backend would have refused for another reason after the download (an - uneditable Gemfile declaration, a Gemfile.lock it cannot edit) also - reports `gem_spec_missing`. `--dry-run` is unchanged: it still fetches - the gem and previews it (`vendor_fetched_missing` + `verified`). - -- **The vendor ledger stores a whole-file snapshot's new text as an edit.** - Several backends record an entire file as a wiring record's `original` / - `new` (maven's `pom.xml`, nuget's config, `pylock*.toml`, PEP 723 scripts - and hatch's project files), so a ledger held two near-identical copies of - that file per vendored package. In `.socket/vendor/state.json` such a - record's `new` text of 1 KiB or more is now written as a line-level edit - of the same record's `original`: `{"snapshot": "", - "ops": [[start, len] | "inserted text", …]}` (a `[start, len]` pair copies - that byte range of the `original`, a string inserts itself), and the - ledger's `"version"` is `2`. The `original` stays the plain string it - always was, every lockfile fragment record (poetry, composer, npm, …) is - untouched, and a ledger without such a record keeps its version-1 bytes. - Every command reads both versions: version-1 ledgers load and revert - exactly as before, and a version-2 edit is rebuilt and checked against its - hash (an edit that does not reproduce its text, has no `original` to - apply to, or any other `{"snapshot": …}` value, is - `vendor_state_unreadable`). Revert, repair, `vex`, rollback and the - re-vendor carry-forward see the same full texts as before. Each record is - self-contained, so an older socket-patch that re-saves the ledger (it - keeps `original` / `new` verbatim) loses nothing; reading a version-2 - record it leaves that fragment alone with its drift warning. No consumer - outside socket-patch reads `state.json` wiring. - -- **A vendored run commits its lockfile and ledger edits once, not per - package.** `vendor`, `scan --mode vendored` and `get --mode vendored` used - to rewrite every touched lockfile / `package.json` / `pnpm-workspace.yaml` - / config and the whole `.socket/vendor/state.json` after EACH package. The - run now captures those edits in memory (every backend still reads its own - and its siblings' earlier edits) and writes the final state once, after - the loop, through a roll-forward journal - (`.socket/vendor/.commit-journal.json`, removed when the commit - completes). The packages that succeeded are committed even when others - failed, so a completed run leaves exactly the files per-package commits - left. Crash semantics move from per-package to per-run: a crash before - the commit leaves the project's lockfiles and ledgers as they were before - the run (the artifacts it wrote are orphans the next run re-vendors over); - a crash during the commit is finished by the next command that takes the - apply lock, before it reads any of those files. When a file the journal - covers was edited since, that file is never written over and the journal - is set aside (`.commit-journal.set-aside-.json`, which keeps every - file's pre-commit bytes; a stderr warning names `repair`): if the edited - files still carry the commit's own lines the rest of the commit is - finished around them (so the ledger records the wiring on disk), if none - of them does the files the crash had already replaced are put back to - their pre-commit bytes, and otherwise nothing is applied. A journal that - would write through a symbolic link, or outside the lockfiles and - ledgers, is set aside unapplied. A replay that fails on I/O keeps the - journal and fails the command's lock acquire (`lock_io`) rather than - letting it work over a half-committed project. A re-vendor under a newer - patch uuid now removes the replaced uuid's artifact dir after the commit, - so its `vendor_stale_artifact_removed` event comes after the run's - per-package events instead of right after the package's own; a golang - takeover likewise deletes the `.socket/go-patches/` copy only after the - commit that repoints `go.mod` away from it. A commit that cannot be - written fails the run with the new top-level error `vendor_commit_failed` - (exit 1), leaving the pre-run lockfiles and ledger in place — or, when - putting back the files already replaced failed too, keeping the journal - (the message says so) for the next locked command to finish the commit. - `repair`, `vendor --revert` and `rollback` keep their per-entry saves. - -- **Vendored artifacts are no longer fsynced one by one.** The files a - vendored run produces under `.socket/vendor///` — patched copy - trees, the `.tgz` / `.whl` / `.nupkg` / `.jar` + `.pom` artifacts and their - `.sha1` sidecars, and the marker — are still written atomically (stage + - rename) but without their own `fsync`/`F_FULLFSYNC`. One durability - barrier syncs every such file and, once per directory, their directories - (with a single `F_FULLFSYNC` per device on macOS) before the next durable - commit point — a lockfile, `go.mod`/`go.sum`, `pom.xml`, `nuget.config`, - `package.json`, `pnpm-workspace.yaml`, the vendor ledger or the redirect - ledger — is written, so nothing durable ever names an artifact that could - still be lost. An artifact rebuilt in place that no commit point follows - (a drifted committed artifact healed with the lockfiles and ledger - unchanged) is synced by the same barrier at the end of the vendored run's - commit and when the command releases the apply lock, so no command - returns with an unsynced artifact the committed state names; a failed - barrier keeps its files pending for the next one. A crash can at worst - lose an artifact nothing durable names yet, which the next run rebuilds - (see `socket_patch_core::utils::durability` for the full argument). The - in-place `apply` of an installed tree keeps its per-file durable writes. - -- **Release publishing decomposed into per-registry workflows.** The - crates.io, npm, PyPI, and RubyGems legs of the `Release` workflow now live - in their own workflows - (`.github/workflows/publish-{cargo,npm,pypi,rubygems}.yml`). A release is - still one dispatch — `release.yml` dispatches each leg at the release tag - (`scripts/dispatch-publish.sh`) and watches it to completion — but after a - mid-release failure any single registry can now also be retried - standalone (Actions → the registry's publish workflow → Run workflow with - the release version) without rebuilding: each leg checks out the - `v` tag and, where binaries are needed, takes them from the - GitHub release's assets verified against `SHA256SUMS` (release-run - dispatches additionally pin the sums file by digest, and same-version leg - runs serialize through a concurrency group). Registry-side - trusted publishers must be re-registered against the new workflow - filenames (the legs always run as top-level `workflow_dispatch` runs, so - every registry's filename matching sees the leg's own file) — see - docs/releasing.md § One-time registry setup. +- Patch application, reversal, and cleanup handle missing files, release variants, + corrupt state, newer ledger formats, and unsafe manifest paths without silently + dropping protection. File ownership restoration failures produce warnings. +- Hosted Cargo handles v1 locks, CRLF files, and repeated declarations, and refuses + transitive dependencies its registry pin cannot reach. Vendored Cargo preserves + multiple versions and warns about old-toolchain limitations. +- Go preserves user-authored replacements, handles `+incompatible` versions, + restores checksums, and unwinds hosted references during vendoring. Registry + fetches honor `GOPROXY` and private-module settings. +- Yarn Berry preserves supported line endings and checksum spellings. Mode + preflights, including Bun's, run before discarding existing protection. +- Composer hosted references remove upstream source fallbacks and mirrors; + RubyGems hosted locks preserve source order; NuGet edits use the active config + and survive `` entries. +- Python rewrites preserve supported markers, groups, extras, source metadata, and + integrity pins. Relocks, out-of-tree environments, and lock-only VEX are handled + consistently with each installer's supported behavior. +- Vendoring reuses valid committed artifacts during service outages. Updates do + not build from a previous patch's modified bytes. Verified service artifacts + keep their identity; integrity failures do not fall through to a local rebuild. + Repair rebuilds against recorded pins and reports unavailable inputs. +- API throttling uses bounded retries, failed queries appear in JSON diagnostics, + and hosted reference resolution handles batches larger than 500 patches. +- Transient apply locks are removed on normal command exit; no-op scans and full + reversal avoid leaving unused `.socket/` state. Terminal output, telemetry + timeouts, and update-check handling are more consistent. + +### Maintenance + +- Shared format models, project snapshots, ledger views, and a vendored backend + consolidate discovery and lifecycle handling. Grouped writes and bounded + concurrency reduce repeated disk and network work. +- CI reuses compiled test binaries and splits broader compatibility matrices into + dedicated jobs. Release publishing uses separate Cargo and npm workflows. +- Documentation now separates usage, configuration, migration, compatibility, and + development guidance; completed plans, prototype research, and historical run + reports are removed from the maintained docs. ## [4.0.0] — 2026-08-20 @@ -2310,7 +232,7 @@ plain (agent), `(vendored)`, and `(redirected)` (hosted). partial writes) on missing hashes, an out-of-namespace module path, a require-version mismatch, or a user-authored replace conflict; references without the override keep the historical `redirect_golang_unsupported` - warning (paid tier stays vendored — see `docs/design/golang-hosted.md`). + warning (paid tier stays vendored — see `docs/ecosystems.md#go-directory-replaces-and-gosum`). Wire schema gains `integrity.goModH1` and `registryOverride.identifiers.goModuleVersion` (additive). Requires server-side publication of the grant-free `gopatch` artifact flavor — @@ -2365,7 +287,7 @@ plain (agent), `(vendored)`, and `(redirected)` (hosted). warns once on stderr and is ignored; `--json` stdout is unaffected. The telemetry endpoint now resolves the API base through the same chain as client construction, so a config-supplied `apiBaseUrl` applies to both. - Design notes: `docs/design/configuration.md`. + Design notes: `docs/configuration.md`. - **Hosted patch mode: `scan --mode hosted` (a.k.a. the hidden `--redirect`).** @@ -2514,7 +436,7 @@ plain (agent), `(vendored)`, and `(redirected)` (hosted). config; Go's module-path identity would force per-grant artifacts against the build-once converter; and the default `GOPROXY` chain would leak licensed bytes / tokened URLs to the public mirror. The full analysis lives - in `docs/design/golang-hosted-no-go.md`; both the CLI rewriter and the + in `docs/ecosystems.md#go-directory-replaces-and-gosum`; both the CLI rewriter and the depscan backend twin emit `redirect_golang_unsupported` naming the remedy (use vendored mode, which gives Go everything hosted promises elsewhere). The one sanctioned exception — an ephemeral-CI GOPROXY recipe — is diff --git a/README.md b/README.md index 9d71e3753..07ac2951a 100644 --- a/README.md +++ b/README.md @@ -1,1548 +1,136 @@ -# Socket Patch CLI +# Socket Patch -Fix known vulnerabilities in the dependencies you already have — without waiting for an -upstream release, and without a risky version bump. +Apply security fixes to the dependency versions your project already uses. +Socket provides patches for specific package versions so you can address known +vulnerabilities without waiting for an upstream release or upgrading the dependency. -Socket's security team backports minimal fixes to the *exact versions* of packages you -use. `socket-patch scan` finds which of your dependencies have a patch and rewrites your -lockfile so that only those dependencies resolve to Socket-hosted, integrity-pinned -patched packages. Your package manager then installs the fix like any other dependency: -no install hook, no CI changes. It works across npm, PyPI, Cargo, Go, RubyGems, Maven, -Composer, NuGet, and Deno. `socket-patch vex` then emits an [OpenVEX -attestation](#openvex-attestations) so your vulnerability scanner stops flagging the CVEs -you've fixed, and `socket-patch scan --mode vendored` commits the patched packages into -your repo when installs must work offline. +The default workflow is **scan → install → vex**: -**Contents:** [Installation](#installation) · [Five-minute tutorial](#five-minute-tutorial) -· [How it works](#how-socket-patch-works) · [Common tasks](#common-tasks) -· [Command reference](#command-reference) · [OpenVEX](#openvex-attestations) -· [Scripting & CI/CD](#scripting--cicd) · [Manifest format](#manifest-format) -· [Ecosystem support →](docs/ecosystems.md) +- `socket-patch scan` finds available patches and updates your dependency files to + use Socket-hosted patched packages. +- Your package manager installs those packages using the updated references and + integrity pins. Commit the files that `scan` reports. +- `socket-patch vex` produces an OpenVEX document describing the vulnerabilities + addressed by those patches. -## Installation - -Install the standalone binary (**recommended**, macOS / Linux): - -```bash -curl -fsSL https://install.socket.dev/patch | sh -``` - -The installer detects your platform, downloads the latest binary, verifies it against -the release's `SHA256SUMS`, and installs to `/usr/local/bin` or `~/.local/bin`. -It needs no language runtime. Set `SOCKET_PATCH_INSTALL_DIR` to choose a directory or -`SOCKET_PATCH_VERSION` to pin a release; pass either variable to `sh` after the pipe. -You can inspect the [installer source](scripts/install.sh) and read about -[mirrors and restricted networks](docs/installer-hosting.md#installing-without-reaching-githubcom). - -On Windows, download a prebuilt -`socket-patch-*-pc-windows-msvc.zip` from the -[latest release](https://github.com/SocketDev/socket-patch/releases/latest), extract it -into a directory on your `PATH`, or install via npm below. The full -[platform list](docs/ecosystems.md#supported-platforms) includes Linux, macOS, Windows, -and Android release archives. - -### Cargo and npm - -These are the supported package-manager distributions: - -| Package manager | Command | -|-----------------|---------| -| cargo | `cargo install socket-patch-cli` (builds from source with every ecosystem compiled in) | -| npm | `npm install -g @socketsecurity/socket-patch` (or one-shot: `npx @socketsecurity/socket-patch`) | - -The npm distribution also supplies Socket Patch to the official -[Socket CLI](https://docs.socket.dev/docs/socket-cli). - -### Updating - -If you installed via the one-liner or a manual download, the CLI updates itself: - -```bash -socket-patch --update # latest release (--update 3.4.0 pins a version) -``` - -It downloads the release for your platform, verifies its SHA-256 against the -published `SHA256SUMS`, and atomically swaps the binary in place. Package-manager -installs are detected and pointed at their own upgrade command instead (e.g. -`npm update -g @socketsecurity/socket-patch`). When a newer release exists, -interactive runs print a once-a-day reminder on stderr — set -`SOCKET_NO_UPDATE_CHECK=1` to turn that off. - -### Migrating from PyPI or RubyGems - -Starting with v5, Socket Patch is distributed as standalone binaries, Cargo crates, -and npm packages. The `socket-patch` PyPI package and Ruby gem, along with -`socket-patch-hook` and `socket-patch-bundler`, are no longer published. -Python and Ruby projects remain fully supported by all three distributions. - -Uninstall the old CLI with the manager that installed it (`pip uninstall socket-patch`, -`pipx uninstall socket-patch`, or `gem uninstall socket-patch`), then use one of the -installation methods above. Remove it from project dependencies and CI bootstrap -commands too. Run `socket-patch --version` to confirm your shell finds the new binary. -Projects that used install hooks should also follow [Upgrading from `setup`](#upgrading-from-setup). - -## Five-minute tutorial - -No account or token is needed to follow along — without an API token `socket-patch` -talks to Socket's public patch proxy, which serves the free tier of patches anonymously. -(An API token unlocks your organization's patch tier; if you've already run -`socket login` with the separate [Socket CLI](https://docs.socket.dev/docs/socket-cli), -`socket-patch` picks it up automatically — see -[Configuration sources](#configuration-sources).) - -**1. Scan.** From your project root: - -```bash -cd your-project -socket-patch scan -``` - -`scan` reads your lockfiles and installed packages, asks Socket which dependency -versions have a patch, prints each one with its severity and CVE/GHSA identifiers, and -patches them in **hosted mode**: it rewrites the lockfile so only the patched -dependencies resolve to Socket-hosted, integrity-pinned packages on `patch.socket.dev`. -It never prompts, keeps no ledger — the lockfile edits are the whole change — and ends by -listing the files it changed. (Add `--dry-run` to preview without writing.) - -> If it prints `No patches available for installed packages.`, none of your dependency -> versions currently has a Socket patch — the good outcome, with nothing to do. To walk -> the rest of the loop anyway, make a scratch project pinned to a version that has a free -> patch — at the time of writing, `flatted@3.3.1`: -> -> ```bash -> mkdir demo && cd demo && git init -q && npm init -y && npm install flatted@3.3.1 && socket-patch scan -> ``` -> -> (The patch catalog changes over time; if that finds nothing, pick another patched -> version.) - -**2. Commit.** The lockfile edit *is* the patch, so commit just the files `scan` -changed — there is no other state to commit (`rollback`, `list` and `vex` read the -lockfile itself): - -```bash -git add package-lock.json .npmrc # npm example -git commit -m "apply Socket security patches" -``` - -The exact files depend on your package manager — `scan` names them. For npm it also -writes `allow-remote=all` to `.npmrc`, which npm 12 needs to install from -`patch.socket.dev` (see [npm: hosted mode and npm 12](#npm-hosted-mode-and-npm-12)); -for pnpm 9+ locks it sets `trustLockfile: true` in `pnpm-workspace.yaml` -([pnpm](#pnpm)). - -**3. Reinstall.** A clean install fetches the patched packages and checks them against -the lockfile's integrity pins: - -```bash -npm ci # or pnpm install, yarn install, pip install -r ..., uv sync, bundle install, ... -``` - -Every later install — yours, your teammates', CI's — does the same. There is no hook to -wire and nothing to add to CI. - -**4. Tell your scanner.** Emit an OpenVEX document that marks each patched CVE -`not_affected`, and hand it to Grype, Trivy or any other VEX-aware scanner: - -```bash -socket-patch vex --output socket.vex.json -grype . --vex socket.vex.json -``` - -**5. See what you have.** `list` shows each patch and the mode that holds it. A hosted -patch is read straight from the lockfile, so it shows its UUID and the files that wire -it (`vex` fetches its full record from the API): - -```bash -socket-patch list -``` - -``` -Found 1 patch: - -Package: pkg:npm/flatted@3.3.1 - UUID: 5cac955f-eab1-4d29-8f4f-c408a6cc9647 - Mode: hosted (wired in package-lock.json) -``` - -**6. Go offline, if you need to.** Hosted installs must reach `patch.socket.dev`. For -airgapped builds, eject to vendored mode with `socket-patch vendor`: it fetches the patch -behind each hosted pin, copies the patched packages into `.socket/vendor/`, and points the -lockfile at them — no manifest needed: - -```bash -socket-patch vendor -git add .socket/vendor package-lock.json .npmrc && git commit -m "vendor Socket patches" -``` - -(Vendored npm installs don't need the `.npmrc` line: the switch deletes the `.npmrc` hosted -mode created, or leaves it with an `npm_allow_remote_left` warning if you added settings to -it.) Each -package is first restored to its upstream registry entry and then vendored, so a later -`socket-patch vendor --revert` returns the project to the plain upstream packages, not to -hosted. After the switch, `list` reads `Mode: vendored (recorded in -.socket/vendor/state.json)` with the patch's full record. - -To undo everything, run `socket-patch rollback`: it restores each hosted lockfile entry to -its upstream registry entry (re-resolved from the registry), reverts vendored wiring, and -drops the records. Where it cannot restore an entry — offline, or a binary `bun.lockb` — -it changes nothing for that package and tells you to restore the file from version control -(`git checkout -- `). - -That's the whole loop: **scan → commit → reinstall → vex**, with `socket-patch vendor` -when installs must be offline. The older *agent* mode, which patches installed files in -place and needs `socket-patch apply` after every install, is still supported; the next section -compares the three. - -## How Socket Patch works - -**A patch** is a minimal fix — usually the upstream security fix, backported — for one -exact published version of a package. Socket distributes it as per-file edits: for each -touched file, the hash of the expected original (`beforeHash`), the hash of the patched -result (`afterHash`), and the replacement content. Patches are looked up by package URL -([PURL](https://github.com/package-url/purl-spec)) — e.g. `pkg:npm/lodash@4.17.20` — so -everything is keyed to exact versions. In hosted and vendored mode your package manager -installs a patched copy of the package, pinned by the lockfile's integrity check; in -agent mode the CLI edits -the installed files itself and verifies every hash before and after (a file matching -neither hash is overwritten with the verified patched content plus a -`content_mismatch_overwritten` warning, unless `--strict` is set). - -### Which patch is picked - -A package version can have several patches (one per advisory, or a later *merged* patch -that folds several advisories into one). `scan` and `get` apply exactly one, chosen -the same way everywhere, from the patches your account can download: - -1. the newest **merged** patch (one covering two or more advisories) wins, regardless of - severity — it is the cumulative fix; -2. otherwise the patch with the worst severity it fixes (critical > high > medium > low), - then the newest; -3. paid tier, then UUID, only break exact ties. - -"Newest" is when the patch was published, not the package version. When a better patch -appears for a package you already patched, the JSON `updates[]` array lists it and the -next `scan` in the same mode takes it. A patch that only wins on the tier or UUID -tiebreak never replaces one you already have, so re-running `scan` never swaps patches. - -This order picks the patch *for* a package. When a capped scan -([`--max-new-patches`](#add-a-few-new-patches-per-run)) has to choose *which packages* -get their first patch, it takes the most severe first, then the ones fixing the most -advisories. - -### State in `.socket/` - -Local state lives in `.socket/` at your project root, and is designed to be committed: - -| Path | Contents | -|------|----------| -| `.socket/vendor/state.json` + `.socket/vendor//…` | Vendored mode: the ledger (with embedded patch records) and the patched package artifacts | -| `.socket/manifest.json` | Agent mode only: the record of downloaded patches — PURLs, file hashes, vulnerability metadata ([format](#manifest-format)) | -| `.socket/blobs/` | Agent mode only: patched file contents, named by git-sha256 hash | - -Hosted mode writes nothing here: its patches live only in your lockfiles (and the -registry configs it edits). Hosted and vendored mode never write `manifest.json`. A -`.socket/vendor/redirect-state.json` from a pre-v5 release is no longer used — `list` -and `vex` read it only for details, and `rollback` deletes it. - -> While a command runs it holds a transient advisory lock, `.socket/apply.lock`, and -> removes it when it finishes — the file never outlives the command, so there is nothing -> to `.gitignore`. A crashed run can leave one behind; the next command reclaims and -> removes it. Nothing in the table is written until there is something to record: a -> report-only `scan`, a `--dry-run`, or a run that changes nothing leaves no `.socket/` at -> all, and a full [`rollback`](#rollback) removes everything it created (only the -> zero-patch `manifest.json` stays). - -### Three patch modes - -The same patched bytes can reach your build three ways. The modes differ in *where the -patch lives* and *what must happen at install time*. `scan --mode ` picks one per -run; a bare `scan` is hosted. - -| Mode | Where the patch lives | Install-time requirement | Trade-off | -|------|----------------------|--------------------------|-----------| -| **hosted** (default) — `scan` | Nowhere in your repo: the lockfile is rewritten so **only** the patched dependencies resolve to Socket-hosted, integrity-pinned packages on `patch.socket.dev`; nothing else is written | Installs must be able to reach `patch.socket.dev` (no CLI, no install hook) | Smallest possible diff (just the lockfile / registry-config edits); not for airgapped installs | -| **vendored** — `scan --mode vendored` or [`vendor`](#vendor) (which ejects a hosted project) | Patched packages committed under `.socket/vendor/`, with the lockfile rewired to consume them | **None** — the package manager installs the committed bytes | Fully airgapped and hermetic, at the cost of repo size | -| **agent** (older) — `scan --mode agent`, [`get`](#get), [`apply`](#apply) | `.socket/manifest.json` + blobs, committed; the CLI patches installed files in place | The `socket-patch` CLI must run after every install (an `apply` step in CI after each install) | No lockfile edits and a small repo footprint, but the only mode that needs a CI change | - -Every mode pins the patched bytes: vendored and hosted modes lean on your package -manager's own lockfile integrity checks (sha512 / sha256 / contentHash / CHECKSUMS) where -the ecosystem enforces them — hosted Maven, which has no lockfile, gets a fail-closed -version-suffixing scheme instead — and agent mode verifies every file on each apply. A -few combinations have weaker install-time pins (vendored Maven, NuGet without a lockfile, -Go's directory replaces, pipenv's Pipfile.lock) — there the committed bytes are the -protection; see the [per-ecosystem caveats](docs/ecosystems.md). - -**Choosing:** use *hosted* unless your installs can't reach `patch.socket.dev`; then -use *vendored*. *Agent* mode remains fully supported for projects already built around -it, and for Deno, which has no hosted or vendored mode. - -Mode support varies by ecosystem — e.g. Rush monorepos can't do vendored, and Go hosted -mode covers the free tier only. See the full -**[mode × ecosystem matrix](docs/ecosystems.md#mode--ecosystem-matrix)** for details. - -### Package-manager notes - -#### npm: hosted mode and npm 12 - -npm 12 defaults to `allow-remote=none` and refuses (`EALLOWREMOTE`) any lockfile -entry whose tarball is not served by your configured registry — which is what a -hosted redirect writes. So when a hosted `scan` (or `get --mode hosted`) leaves a -`package-lock.json` / `npm-shrinkwrap.json` pointing at `patch.socket.dev`, it also -writes `allow-remote=all` to the project `.npmrc` (creating it, or appending one line -and keeping everything else byte-for-byte) and warns `redirect_npm_allow_remote`. -Commit the `.npmrc` with the lock; a plain `npm ci` then installs the patched -packages on every npm from 7 to 12. The tradeoff: `allow-remote=all` lets npm install -**any** URL-resolved dependency, not just Socket's patched ones — the per-entry sha512 -integrity pins are still enforced. An explicit `allow-remote=none` / `root` of yours is -never changed or overridden — whether it sits in the project `.npmrc`, in your user -(`~/.npmrc`), global or builtin npm config, or in an `npm_config_allow_remote` -environment variable (the warning names where it found it and how to install anyway), -`--no-npm-allow-remote-config` -(`SOCKET_NO_NPM_ALLOW_REMOTE_CONFIG`) turns the write off (install with -`npm ci --allow-remote=all` instead). Once `rollback` / `remove` / switching to vendored -mode has restored the last hosted `package-lock.json` entry, an `.npmrc` that holds only -`allow-remote=all` is deleted; if you have other settings in it, the line is left alone -with an `npm_allow_remote_left` warning (hosted mode keeps no record of whether it added -the line). Vendored mode needs none of this: -npm treats its `file:` tarballs under `allow-file`, which defaults to `all`. See -[npm compatibility](docs/testing/npm-compatibility.md) for the tested majors. - -#### pnpm - -For a lockfileVersion 9 `pnpm-lock.yaml`, hosted mode also sets `trustLockfile: true` in -`pnpm-workspace.yaml` (pnpm 11+ rejects the redirected lock without it; commit the file -with the lock) unless the project disables it or you pass `--no-trust-lockfile-config`. -It skips pnpm's registry re-verification for the whole lock, while tarball integrity -stays enforced. A warm store can keep serving the upstream bytes, so reinstall from a -clean tree and an empty store, then check with `socket-patch vex`. See -[pnpm compatibility](docs/testing/pnpm-compatibility.md). - -#### Bun - -Both text `bun.lock` and binary `bun.lockb` support hosted and vendored -patches, mode switching, repair, and rollback — with one exception: a hosted -`bun.lockb` entry is not rolled back to its upstream registry entry, so -`rollback` and `remove` refuse it and point you at `git checkout -- bun.lockb` -(switching it to vendored mode rebuilds the registry entry and works). Binary locks are read and -patched natively: Socket Patch does not need Bun installed to discover or -rewrite them, and does not convert them to text. If both filenames exist, -`bun.lock` takes precedence. See [Bun compatibility](docs/testing/bun-compatibility.md) -for the tested versions, workspace behavior, and installer integrity limits. - -#### vlt - -[vlt](https://www.vlt.sh) projects (`vlt-lock.json`) work in agent and hosted mode on -every vlt release from 0.0.0-1 to 1.2.0, and in vendored mode on locks with -`lockfileVersion` 0 or 1 (0.0.0-19 and later; older locks are refused with -`vendor_lockfile_version_unsupported`). Hosted mode checks that each artifact is served -the way vlt can verify and removes stale installed copies so the next `vlt install` -fetches the patched packages. Vendored mode covers direct dependencies of the root or a -workspace member (transitive dependencies need hosted mode); after vendoring an optional -dependency run `vlt ci`. See [vlt notes](docs/ecosystems.md#npm-vlt-notes) for the -caveats and [vlt compatibility](docs/testing/vlt-compatibility.md) for the tested -releases. - -#### Pipenv +Use `socket-patch vendor` to put the selected patched packages in your repository +when installs must work without Socket's patch server. -Hosted mode rewrites every `Pipfile.lock` category that pins the patched release and -keeps the Pipfile, its content hash, markers and unrelated entries, so `pipenv install ---deploy`, `pipenv sync` and `pipenv verify` keep passing (Pipenv 7 and later; older -lock formats are refused unchanged). Socket Patch probes `pipenv --version` once per run -to pick the reference shape; `SOCKET_PIPENV_MAJOR=` pins it on machines without -pipenv. Vendored mode requires Pipenv 2018 or later; Pipenv 2023+ does not hash-check -local wheels, so commit the wheel and run `socket-patch vex --product ` (a Pipfile -names no project). A clone with only `Pipfile` + `Pipfile.lock` works in every mode. +> This branch documents the v5 prerelease. Installation commands below select the +> latest published release, which may have different behavior. To try this branch, +> [build from source](docs/development.md#build). Existing users should read the +> [v5 migration guide](docs/migrating-to-v5.md). -Pipenv never reinstalls a release that is already present, so a rewrite protects fresh -installs, and Socket Patch warns (`redirect_pypi_stale_install` / -`pypi_pipenv_stale_install`) when a venv still holds the upstream release, with the -remedy `pipenv run pip uninstall -y && pipenv sync`. Don't use `pipenv uninstall -` for this — it re-locks the patch away — and re-run `scan` after `pipenv lock` / -`pipenv update`, which regenerate the entry to its registry reference. Measured -boundaries are in [Pipenv compatibility](docs/testing/pipenv-compatibility.md). - -## Common tasks - -### Patch everything that can be patched - -```bash -socket-patch scan # hosted mode: rewrite lockfiles (never prompts) -socket-patch scan --dry-run # preview what it would change -socket-patch scan --json # same run, machine-readable result -``` - -### Patch only some packages, or some projects in a monorepo - -```bash -socket-patch scan --package lodash --package pkg:pypi/requests # or --package lodash,requests -socket-patch scan apps/web apps/api # each PATH is a project directory -socket-patch scan 'services/*' # directory globs work too -``` - -`--package` takes a name (case-insensitive) or a purl with or without its version. In -hosted and vendored mode each PATH is a project directory, scanned as if it were -`--cwd` under an `== ==` header; the worst exit code wins. - -To make the choice stick for everyone who runs `scan` in the repo (CI and the Socket -autopatch bot included), put it in `socket.yml` instead — see -[Roll out gradually](#roll-out-gradually-with-socketyml). -### Add a few new patches per run - -```bash -socket-patch scan --max-new-patches 5 # at most 5 packages get their first patch -socket-patch scan --max-new-patches 0 # only upgrade patches you already have -socket-patch scan --max-new-patches none # no cap this run -``` - -A capped scan patches the most critical packages first: by the severity of the patch, -then by how many advisories it fixes. Upgrades of packages that are already patched are -never capped. Commit the result and run `scan` again to add the next batch; repeated -runs on an unchanged repo add the same packages in the same order and stop once -everything is patched. `--dry-run` shows exactly what the run would add and defer, and -`--json` reports it under `rollout` (`jq '.rollout.counts.deferred'`). In hosted and -vendored mode, several project directories in one run (`scan apps/*`) share the cap, -visited in sorted order; `--json` takes one directory, so a CI job per directory gets -its own N. - -To drip patches in through a PR bot, set the cap once in the repo's `socket.yml` -(part of its [`patches:` policy](#roll-out-gradually-with-socketyml); the flag and -`SOCKET_MAX_NEW_PATCHES` override it, and `--no-socket-yml` ignores it): - -```yaml -# Weekly drip with the depscan autopatch PR -version: 2 -patches: - maxNewPatches: 5 # the PR keeps the same 5 until merged, then the next 5 -``` - -A cap only advances when the scan's changes are committed (or merged by a PR bot). In a -CI job that scans without committing, set no cap. - -### Patch one specific CVE or advisory - -```bash -socket-patch get CVE-2024-12345 --mode hosted -socket-patch get GHSA-xxxx-yyyy-zzzz --mode hosted -``` - -Like `scan`, `get` defaults to hosted mode; `--mode vendored` or `--mode agent` -(in-place apply, also implied by `--save-only` and `--global`) picks the others. - -### Check for patches in CI without changing anything - -```bash -socket-patch scan --json --dry-run | jq '{patches: .totalPatches, updates: (.updates | length)}' -``` - -### Run an auto-update bot in CI - -```bash -socket-patch scan --json -``` - -A hosted scan takes new patches and newer versions of the ones already applied. Your PR -tooling (e.g. `peter-evans/create-pull-request`) commits the changed lockfiles and -registry configs (hosted mode writes nothing else); use the JSON result for the PR title/body. See -[Scripting & CI/CD](#scripting--cicd), including how to supply `SOCKET_API_TOKEN` for -org-tier patches. - -### Tell your vulnerability scanner about the patches - -```bash -socket-patch vex --output socket.vex.json -grype --vex socket.vex.json # or trivy image --vex ... -``` - -The OpenVEX document marks each patched CVE `not_affected`. Run it after installing, so -hosted patches are hash-verified against the installed copies. You can also emit it -inline with `scan --vex `. Details in [OpenVEX attestations](#openvex-attestations). - -### Work offline / airgapped - -```bash -socket-patch vendor # ejects a hosted project; or: socket-patch scan --mode vendored -git add .socket/vendor -``` - -`socket-patch vendor` in a hosted project (no manifest) fetches the patch behind each -hosted lockfile pin and vendors it; `scan --mode vendored` discovers and vendors from -scratch. Either way a hosted package is restored to its upstream registry entry before it -is vendored, so `socket-patch vendor --revert` later returns to upstream. Vendored mode needs no Socket infrastructure and no `socket-patch` binary at install -time — the patched packages install from the committed bytes (other, unvendored -dependencies still resolve from your registry or mirror as usual). Agent mode also works -offline once its blobs are committed (`socket-patch apply --offline`). `scan` and `get` -need the network and refuse to run with `--offline`. - -### Undo things - -| Command | What it does | -|---------|--------------| -| [`rollback`](#rollback) | **Fully unpatches, in every mode**: restores each hosted lockfile entry to its upstream registry entry (re-resolved from the registry; refused with a `git checkout -- ` hint where that is impossible, e.g. offline or `bun.lockb`), unwinds vendored lockfile wiring, restores in-place files, and drops the records — everything, or just the given targets; `--preserve-state` keeps the local patch state for a later re-apply | -| [`remove`](#remove) | The single-patch form of `rollback`: restore, unwind, drop the record and GC for one PURL/UUID (a hosted patch is restored to upstream) | -| [`vendor --revert`](#vendor) | **Un-vendors wholesale**: restores the recorded original lockfile fragments byte-for-byte and removes the `.socket/vendor/` artifacts (a package vendored over a hosted pin returns to upstream, not to hosted) | -| [`scan --prune`](#scan) | Agent mode: **reconciles, doesn't reverse** — drops manifest entries for packages that have left the project and garbage-collects orphan blob/diff/archive files | -| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, re-vendors missing/corrupt vendored artifacts, and cleans up unused ones | - -> Reverting a hosted edit by hand (e.g. `git checkout -- `) is always safe: -> hosted mode keeps no other state, so there is nothing else to clean up. - -## Command reference - -| Command | What it does | -|---------|--------------| -| [`scan`](#scan) | Find patches for your dependencies and apply them — by default by rewriting lockfiles to Socket-hosted patched packages | -| [`vex`](#vex) | Generate an OpenVEX document for the vulnerabilities the project's patches fix | -| [`vendor`](#vendor) | Eject patched dependencies into committable `.socket/vendor/` and rewire lockfiles to use them (`--revert` undoes it) | -| [`list`](#list) | List the patches in this project: hosted and vendored records plus any agent-mode manifest entries | -| [`get`](#get) | Patch one package, CVE, GHSA or patch UUID (hosted by default; alias: `download`) | -| [`remove`](#remove) | Unwind one patch by PURL or UUID, in any mode | -| [`rollback`](#rollback) | Unwind every patch, in any mode: restore original files and hosted or vendored lockfile wiring | -| **[Agent mode](#agent-mode)** | | -| [`apply`](#apply) | Apply the patches in `.socket/manifest.json` in place (run it after every install) | -| [`repair`](#repair) | Download missing patch artifacts, re-vendor broken vendored artifacts, clean up unused ones (alias: `gc`) | - -`socket-patch --update` updates the CLI itself (see [Updating](#updating)). - -### Global options - -These flags are accepted by **every** subcommand and go after the command name — -`socket-patch --json --cwd ./app` works uniformly (`socket-patch --json -` is a parse error). A command silently ignores any global flag it doesn't use -(e.g. `list --global` parses fine and the flag is a no-op). - -Each flag has a matching `SOCKET_*` environment variable, listed in the table; -command-specific flags list theirs in each command's own table. **Precedence is CLI arg -> env var > default** — with one extra fallback layer for the three authentication -settings, described in [Configuration sources](#configuration-sources) below. - -| Flag | Env var | Description | -|------|---------|-------------| -| `--cwd ` | `SOCKET_CWD` | Working directory (default: `.`). The manifest path is resolved relative to this. | -| `--manifest-path ` | `SOCKET_MANIFEST_PATH` | Path to the patch manifest, resolved relative to `--cwd` (default: `.socket/manifest.json`). | -| `--api-url ` | `SOCKET_API_URL` | Socket API URL for the authenticated endpoint (default: `https://api.socket.dev`). | -| `--api-token ` | `SOCKET_API_TOKEN` | Socket API token — optional. When no token resolves from any source, the anonymous public patch proxy is used (free patches). See [Configuration sources](#configuration-sources) for how to obtain and persist one. | -| `-o, --org ` | `SOCKET_ORG_SLUG` | Organization slug. Auto-resolved when omitted and a token is set. | -| `--proxy-url ` | `SOCKET_PROXY_URL` | Public proxy URL used when no API token is set (default: `https://patches-api.socket.dev`). | -| `-e, --ecosystems ` | `SOCKET_ECOSYSTEMS` | Restrict to specific ecosystems (comma-separated, e.g. `npm,pypi`). Unknown names are rejected. | -| `--download-mode ` | `SOCKET_DOWNLOAD_MODE` | Artifact to fetch when local files are missing: `diff` (default, smallest delta) or `file` (legacy per-file blobs). | -| `--vendor-source ` | `SOCKET_VENDOR_SOURCE` | How vendored mode acquires the installable artifact: `auto` (default — download the prebuilt package from patch.socket.dev, fall back to a local build on any miss), `service` (require the service, fail-closed), or `build` (always build locally). Covers npm, pypi, cargo, golang, composer, gem, nuget, and maven. | -| `--vendor-url ` | `SOCKET_VENDOR_URL` | Base host for the vendoring service's package-reference request (default: the active `--api-url`/`--proxy-url` base). Point at staging / local dev for testing. | -| `--patch-server-url ` | `SOCKET_PATCH_SERVER_URL` | Override the host of the prebuilt-archive download URL the service returns (default: as returned). Mainly for local-dev / testing. | -| `--offline` | `SOCKET_OFFLINE` | Strict airgap: never contact the network. Operations that need remote data fail loudly. | -| `--strict` | `SOCKET_STRICT` | Fail-closed on before-hash mismatches instead of the default warn-and-overwrite: a file whose current content matches neither `beforeHash` nor `afterHash` aborts that package's apply. Overridden by `--force`. | -| `-g, --global` | `SOCKET_GLOBAL` | Operate on globally-installed packages. | -| `--global-prefix ` | `SOCKET_GLOBAL_PREFIX` | Override the path used to discover globally-installed packages. | -| `-j, --json` | `SOCKET_JSON` | Emit machine-readable JSON output. Every JSON response includes a `"status"` field — camelCase on the envelope commands (`"success"`, `"error"`, `"noManifest"`, `"partialFailure"`, `"paidRequired"`, `"notFound"`; apply/list/repair/remove/vendor), snake_case on the legacy shapes (`"partial_failure"`, `"not_found"`; get/scan/rollback). See [CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md) for the exact shapes. | -| `-v, --verbose` | `SOCKET_VERBOSE` | Show extra detail in human-readable output. | -| `-s, --silent` | `SOCKET_SILENT` | Suppress non-error output. | -| `--dry-run` | `SOCKET_DRY_RUN` | Preview the operation without making any mutations. | -| `-y, --yes` | `SOCKET_YES` | Skip confirmation prompts (`get`, `rollback`, `remove`, `--update`). `scan` never prompts, so it ignores this flag. | -| `--lock-timeout ` | `SOCKET_LOCK_TIMEOUT` | Seconds to wait for `.socket/apply.lock` before giving up. `0`/unset = a single non-blocking try; a positive value retries with backoff. Only meaningful for the commands that take the lock — `apply`, `rollback`, `repair`, `remove`, `vendor`, and `scan`/`get` whenever they write (agent-mode download + apply, vendored, hosted). The lock file exists only while a command runs. | -| `--debug` | `SOCKET_DEBUG` | Emit verbose debug logs to stderr. | -| `--no-telemetry` | `SOCKET_TELEMETRY_DISABLED` | Disable anonymous usage telemetry. | -| `--no-npm-allow-remote-config` | `SOCKET_NO_NPM_ALLOW_REMOTE_CONFIG` | Hosted mode: don't write `allow-remote=all` to the project `.npmrc` (see [npm compatibility](#npm-hosted-mode-and-npm-12)). | -| `--no-trust-lockfile-config` | `SOCKET_NO_TRUST_LOCKFILE_CONFIG` | Hosted mode: don't set `trustLockfile: true` in `pnpm-workspace.yaml` for a lockfileVersion 9 pnpm lock (pnpm 11+ then needs `pnpm install --trust-lockfile`). | -| `--no-vlt-install-cleanup` | `SOCKET_NO_VLT_INSTALL_CLEANUP` | Hosted mode: don't remove stale vlt installed copies after `vlt-lock.json` is repointed or restored (run `vlt ci` instead). | - -#### Configuration sources - -For the three authentication settings, the [Socket CLI](https://docs.socket.dev/docs/socket-cli)'s -persisted login sits between the env var and the built-in default — run `socket login` -(or `socket config set apiToken` / `defaultOrg`) once and `socket-patch` picks it up -too. The `SOCKET_CLI_*` env vars the JS CLI reads are honored as peer aliases as well, -so one export configures both tools. To set a token directly instead, create one in the -[Socket dashboard](https://socket.dev) under your organization's API tokens settings and -use the raw token (`sktsec_<...>_api`) shown at generation time, **not** the -`sha512-...` display hash. Resolution is per key, and an empty value means "unset" at -every layer: - -``` ---api-token / --org / --api-url - 1. CLI flag - 2. Env var SOCKET_API_TOKEN / SOCKET_ORG_SLUG / SOCKET_API_URL — or the - SOCKET_CLI_* peer aliases (SOCKET_CLI_API_TOKEN / - SOCKET_CLI_ORG_SLUG / SOCKET_CLI_API_BASE_URL); the - canonical name wins when both are set - 3. socket-cli config /socket/settings/config.json — read-only - (Linux: $XDG_DATA_HOME, else ~/.local/share; - macOS: $XDG_DATA_HOME, else ~/Library/Application Support, - then legacy ~/.local/share; Windows: %LOCALAPPDATA%) - 4. Built-in default no token → public proxy; org → auto-resolve; - url → https://api.socket.dev -``` - -Two env-only toggles adjust this. `SOCKET_NO_API_TOKEN=1` ignores ambient tokens (env + -config; an explicit `--api-token` still wins) — useful to force the anonymous public -proxy in CI or a test run. `SOCKET_NO_CONFIG=1` disables the config-file layer entirely. -`socket-patch` never *writes* the config file, and a corrupt one only produces a stderr -warning — it never breaks a command or pollutes `--json` output. `socket-patch` does -**not** read `.env` files or any per-repository config for endpoints or credentials: a -cloned repo must never be able to redirect where patches come from or spend your token. -(Full rationale: [docs/design/configuration.md](docs/design/configuration.md).) - -Three env-only knobs tune pacing rather than routing: - -- `SOCKET_API_CONCURRENCY=` (clamped to `1`-`32`) caps in-flight patch-API requests. - By default `scan` runs a quarter of a step's requests at once, between 8 and 32, against - the authenticated API, and 4 against the public proxy (where the knob can only lower - it); `vex` record fetches run up to 10 (4 on the proxy). Lower it when a self-hosted - `--api-url`, corporate proxy, WAF or CDN caps requests per client and a scan starts - reporting fewer patches than it should. -- `SOCKET_API_MAX_RETRIES=` (`0`-`10`, default 3) sets how often a `429` / `503` - answer is retried. Retries honor `Retry-After` (a wait over 30 s gives up at once) or - back off 0.5 s, 1 s, 2 s with jitter, and all retries in a run must finish within 60 s. - Other errors are never retried. A query still failing is reported, never dropped - (`Warning: API batch of failed: …`, or `api_batch_failed` / - `patch_details_failed` in `--json` `warnings[]`); if every query fails the scan exits 1. -- `SOCKET_WALK_THREADS=` (clamped to `1`-`16` and the CPU count; default 4, fewer on small machines) sizes the - thread pool for the `node_modules` and Maven repository walks. A soft open-file limit - below 128 forces one thread. - -An unset, empty or non-numeric value leaves the default in place. - -The sections below list only each command's **command-specific** flags. - -### `scan` - -Find patches for your dependencies and apply them. `scan` is the entry point for all -three [patch modes](#three-patch-modes): - -- **hosted** (the default — a bare `scan`, `scan --json` included) rewrites lockfiles / - registry configs so only the patched dependencies resolve to Socket-hosted packages - (the lockfile edits are the only record — no ledger); -- `--mode vendored` discovers, downloads, and builds + wires the committable - `.socket/vendor/` artifacts in one pass (re-vendoring automatically when a newer patch - is selected), writing no `.socket/manifest.json`. It works on a fresh clone: - dependencies listed in the lockfile but not yet installed are fetched pristine from - their registry and integrity-verified against the lockfile before vendoring; -- `--mode agent` downloads the selected patches into `.socket/manifest.json` + blobs and - applies them to the installed files in place. - -`scan` never prompts, in any mode — `--yes` changes nothing. Use `--dry-run` to preview -any run. A `--prune` or `--global` / `--global-prefix` scan with no mode is the one -report-only case: it lists what it found (plus, with `--prune`, runs the agent-mode -garbage collection) and prints `To apply these patches in place, run: socket-patch scan ---mode agent [PATHS]`. Hosted mode cannot be combined with `--global`. +## Installation -When a package has several patches, `scan` applies the one described in -[Which patch is picked](#which-patch-is-picked). The JSON `updates[]` array lists -packages whose recorded patch has been superseded — agent manifest entries, vendored -entries, and hosted pins read from the lockfiles — and the next -`scan` in that mode takes the newer patch. +Install a standalone binary on macOS or Linux: -**Usage:** -```bash -socket-patch scan [PATHS]... [options] +```sh +curl -fsSL https://install.socket.dev/patch | sh ``` -**Arguments:** -- `PATHS` — restrict the scan. In hosted and vendored mode each PATH (or directory glob, - e.g. `apps/*`) is a **project directory**, scanned on its own as if it were `--cwd`, - under an `== ==` header; the worst exit code wins. A PATH that is not a - directory exits 2, and `--json` accepts only one directory. In agent mode PATHS are - globs over **installed package paths** (a bare directory scopes its whole subtree; - `--prune` still considers the whole project, and lockfile-only packages are left out - with a warning). - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `--mode ` | — | Selects one of the three [patch modes](#three-patch-modes) (default: `hosted`). Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. | -| `--package ` | `SOCKET_SCAN_PACKAGES` | Only scan these packages: a name (`lodash`, `@scope/pkg`, `requests`; case-insensitive) or a purl with or without its version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`). Repeat the flag or separate with commas. | -| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff-archive files (plus any legacy package archives). [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. | -| `--sync` | — | Shorthand for `--mode agent --prune`: the one-flag agent-mode auto-update run. | -| `--max-new-patches ` | `SOCKET_MAX_NEW_PATCHES` | Add at most N patches to packages that have none yet, most severe first; the rest are deferred to the next scan and listed in the output. Upgrades of already-patched packages are not capped. `0` adds no new patches, `none` means no cap (it also lifts a `socket.yml` `patches.maxNewPatches`). See [Add a few new patches per run](#add-a-few-new-patches-per-run). | -| `--batch-size ` | `SOCKET_BATCH_SIZE` | Packages per API request (default: `500` on the authenticated API, `100` on the public proxy). A request whose body would exceed 256 KiB is split into smaller ones. | -| `--min-severity ` | `SOCKET_MIN_SEVERITY` | Only patch packages whose patch fixes an advisory of at least `critical`, `high`, `medium` (or `moderate`) or `low`; `none` lifts the floor. Overrides `patches.minSeverity` in socket.yml. Patches of unknown severity are skipped whenever a floor is set. | -| `--no-socket-yml` | `SOCKET_NO_SOCKET_YML` | Ignore the repo's socket.yml patch policy for this run (the built-in test/fixture directory ignores still apply). | -| `--all-releases` | `SOCKET_ALL_RELEASES` | Store patches for every release/distribution variant, not just the installed one — PyPI wheel/sdist, RubyGems platform, Maven classifier. Makes the manifest portable across environments (e.g. cross-platform CI caches). | -| `--vex ` | `SOCKET_VEX` | On a successful scan, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX](#inline-vex-on-apply--scan--vendor). | -| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. | - -> Deprecated, hidden spellings (still accepted): `--apply` (== `--mode agent`) and -> `--vendor` (== `--mode vendored`). - -**Examples:** -```bash -# Hosted mode (default): rewrite lockfiles to Socket-hosted patched packages -socket-patch scan - -# Same, JSON output -socket-patch scan --json - -# Preview without writing anything -socket-patch scan --json --dry-run - -# Only npm packages / only one package -socket-patch scan --ecosystems npm -socket-patch scan --package lodash - -# Two projects of a monorepo -socket-patch scan apps/web apps/api - -# Roll out gradually: at most 5 new patches, most critical first -socket-patch scan --max-new-patches 5 +The installer verifies the download against the release's `SHA256SUMS` and installs +in `/usr/local/bin` or `~/.local/bin`. To choose a directory or release, pass +`SOCKET_PATCH_INSTALL_DIR` or `SOCKET_PATCH_VERSION` to `sh` after the pipe. +See the [installer source](scripts/install.sh) and +[mirror configuration](docs/installer-hosting.md). -# Vendored mode: build + commit every patched dependency -socket-patch scan --json --mode vendored +On Windows, extract a `socket-patch-*-pc-windows-msvc.zip` archive from +[GitHub Releases](https://github.com/SocketDev/socket-patch/releases) into a directory +on your `PATH`, or install through npm: -# Agent mode: patch installed files in place -socket-patch scan --json --mode agent - -# Agent-mode auto-update: discover, apply, garbage-collect -socket-patch scan --json --sync - -# Report-only scan of global packages -socket-patch scan -g - -# Hosted mode + an OpenVEX attestation in one pass -socket-patch scan --vex socket.vex.json +```sh +npm install -g @socketsecurity/socket-patch ``` -> Already-vendored packages are **skipped by an agent-mode scan** (the committed -> artifact is the patch); a newer available patch still appears in `updates[]` — re-run -> `scan --mode vendored` to take it. +Cargo users can build and install the published CLI with +`cargo install socket-patch-cli`. All distributions support the same ecosystems; +you do not need Node.js or Rust to use the standalone binary. -#### Roll out gradually with socket.yml +For standalone installs, run `socket-patch --update` to update. For npm or Cargo +installs, use that package manager's update command. The +[platform matrix](docs/ecosystems.md#supported-platforms) lists release targets. -A `patches` block in the repo-root `socket.yml` (the file the Socket scanner already -reads; keep `version: 2`) narrows what `scan` may patch, for every mode and for the -in-memory engine behind the Socket autopatch bot. It can only narrow: nothing in it can -name an endpoint or token, pick a mode, or turn off a safety check. +## Quick start -```yaml -# Critical first: widen by editing one line -version: 2 -patches: - minSeverity: critical # later: high, then low, then remove the key - # (low still skips patches whose severity is unknown) -``` +From the root of a project with dependency files: -```yaml -# One directory first (monorepo) -version: 2 -patches: - includePaths: - - "/services/payments/" - # add "/services/checkout/" next sprint +```sh +socket-patch scan --dry-run # preview available patches and edits +socket-patch scan # apply hosted references; never prompts ``` -```yaml -# One ecosystem, hold one package -version: 2 -patches: - ecosystems: [npm] - ignorePackages: ["pkg:npm/left-pad"] -``` - -```yaml -# Pause: report only; existing patches stay in place -version: 2 -patches: - enabled: false -``` - -- Paths are gitignore patterns (the same rules as `projectIgnorePaths`, which scan now - honors too), matched against each project's lockfiles: `"/services/payments/"`, - `"**/yarn.lock"`, `"examples/**"`. `test/`, `tests/`, `fixtures/`, `__fixtures__/` - and `testdata/` directories are skipped by default when scan discovers projects - (a directory glob such as `scan 'services/*'`); re-include one with a negation - (`ignorePaths: ["!/e2e/tests/"]`). A directory you name yourself is always scanned. - (The autopatch bot's tree listing skips those directories before it reads - socket.yml, so there a negation cannot bring one back.) -- `packages` / `ignorePackages` take `--package` specs; prefer purls (`pkg:npm/core`), - because a bare name also matches other ecosystems and scoped packages (`core` - matches `@babel/core`). -- Narrowing never removes a patch: a package that already carries one and is now - filtered out is left exactly as it is (reported under `policy.retained[]`). Use - `rollback` or `remove` to take a patch out. -- A broken file fails the scan (exit 1, `errorCode: socket_yml_invalid`) before anything - is written, with the key and the fix in the message — a typo never widens the - rollout. `--no-socket-yml` ignores the file for one run. -- `scan --json` reports what the policy did in a top-level `policy` block - (`jq '.policy.counts'`); the human output adds a `Policy (socket.yml): …` line that - names every skipped project and every critical/high patch the severity floor held - back (`--verbose` lists everything). `get` ignores the policy (explicit - intent) and warns `policy_bypassed`. - -Every key: `enabled`, `includePaths`, `ignorePaths`, `ecosystems`, `packages`, -`ignorePackages`, `minSeverity`, `maxNewPatches` — see CLI_CONTRACT.md "socket.yml patch -policy" for the full grammar, precedence and validation rules. +Without an API token, the CLI uses Socket's public proxy for free patches. +To use your organization's patch tier, set `SOCKET_API_TOKEN`, or sign in with the +separate Socket CLI using `socket login`. See [configuration](docs/configuration.md). -### `vex` +A scan with no available patches means the catalog has no applicable patch for +this run. It is **not** a finding that the project has no vulnerabilities. -Generate an [OpenVEX](https://github.com/openvex) 0.2.0 attestation describing the -vulnerabilities that the applied patches have mitigated — agent-mode patches from the -manifest, and hosted / vendored patches straight from the lockfiles (no manifest needed). -See [OpenVEX attestations](#openvex-attestations) below for the full workflow. +Review and commit the files the scan changed. Hosted mode keeps no patch ledger; +its state is in the project's lockfiles, manifests, and package-manager configuration. +For example, an npm project may change both `package-lock.json` and `.npmrc`: -**Usage:** -```bash -socket-patch vex [options] -``` - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `-O, --output ` | `SOCKET_VEX_OUTPUT` | Write the VEX document to this path instead of stdout. Required when combined with `--json`. | -| `--product ` | `SOCKET_VEX_PRODUCT` | Override the auto-detected top-level product PURL/identifier. | -| `--no-verify` | `SOCKET_VEX_NO_VERIFY` | Skip the on-disk file-hash check and trust the patch records — useful on a build machine that doesn't have the patched files laid out. The wiring checks still apply: a vendored ledger record the lockfile no longer wires, or a lockfile reference whose record is unavailable or names another package, is omitted either way. | -| `--doc-id ` | `SOCKET_VEX_DOC_ID` | Override the document `@id`. Default is a random `urn:uuid:` regenerated each run; pin this for a reproducible identifier. | -| `--compact` | `SOCKET_VEX_COMPACT` | Emit compact JSON instead of pretty-printed. | - -**Examples:** -```bash -# Print a VEX document to stdout (human-readable status goes to stderr) -socket-patch vex - -# Write the document to a file +```sh +git diff +git add package-lock.json .npmrc +git commit -m "Apply Socket security patches" +npm ci socket-patch vex --output socket.vex.json - -# CI shape: VEX doc to file, machine-readable envelope to stdout -socket-patch vex --json --output socket.vex.json - -# Generate on a build box without verifying on-disk files -socket-patch vex --no-verify --output socket.vex.json -``` - -### `vendor` - -The command behind [vendored mode](#three-patch-modes). Instead of patching installed -packages in place, it ejects each patched package into -`.socket/vendor///…` and rewires your lockfile so the project -consumes the vendored copy. Commit `.socket/vendor/` (the artifacts plus the ledger whose -embedded patch records [`vex`](#vex), [`list`](#list) and [`repair`](#repair) read) -along with the lockfile edits, and **every fresh checkout builds with the patched -dependency**: no `socket-patch` binary, no Socket API access and no install hook on the -consuming machine. - -There are two ways in: - -- **`socket-patch vendor`** vendors the agent-mode patches listed in - `.socket/manifest.json`. With no manifest in a **hosted** project it **ejects**: it - takes the patch set from the lockfiles' hosted pins, fetches each patch from the API, - and vendors it (`Ejecting N hosted packages into .socket/vendor/...`). This is the way - to move a hosted project offline (run it while online; it works from a fresh checkout). - The eject is all-or-nothing: if any patch can't be fetched or vendored, the project is - left hosted exactly as it was. With neither a manifest nor hosted pins (a - `scan --mode vendored` project) it has nothing to vendor and says so; `vendor --revert` - works either way. -- **`socket-patch scan --mode vendored`** discovers, downloads and vendors in one pass, - writes no `.socket/manifest.json`, and takes over packages a hosted scan redirected. - -Taking over a hosted package (either way) first restores its upstream registry entry — -the same restore `rollback` does — so `vendor --revert` later returns it to upstream, -never back to hosted. A package whose entry cannot be restored (offline, `bun.lockb`) -fails with `redirect_revert_failed` and stays hosted. - -Vendoring is per-patch: only dependencies with a Socket patch are vendored. For the -lockfile flavors each ecosystem supports, see the -[mode × ecosystem matrix](docs/ecosystems.md#mode--ecosystem-matrix). - -**Usage:** -```bash -socket-patch vendor [options] -socket-patch scan --mode vendored [PATHS]... [options] -``` - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `-f, --force` | `SOCKET_FORCE` | Tolerate *missing* patch-target files in the staged copy (skipped instead of failing the vendor) and bypass the variant probe for multi-release ecosystems. A plain before-hash mismatch doesn't need this: vendor staging always overwrites mismatched content with the verified patched bytes (surfaced as a `vendor_content_mismatch_overwritten` warning). | -| `--revert` | `SOCKET_VENDOR_REVERT` | Undo vendoring: restore the recorded original lockfile fragments byte-for-byte and remove the `.socket/vendor/` artifacts. Works without a manifest. A package vendored over a hosted pin returns to its upstream registry entry. | -| `--vex ` | `SOCKET_VEX` | On a successful vendor, also write an OpenVEX 0.2.0 document to this path. | -| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder. Inert unless `--vex` is set. | - -**How it interacts with the rest of the CLI** — once a package is vendored, `vendor` owns -it: - -- [`apply`](#apply) and [`rollback`](#rollback) skip vendored packages (they never touch - a vendor-owned tree or lockfile entry). -- [`remove`](#remove) **reverts the vendoring** as part of removing the patch — lockfile - restored, artifact deleted — so one command fully undoes it. -- An agent-mode [`scan`](#scan) skips vendored packages, and `--prune` exempts them - from its crawl-based prune (though a vendored entry whose dependency has left the - lockfile is reverted and dropped); newer patches show up in `updates[]` as the signal - to re-run `scan --mode vendored`. -- [`vex`](#vex) attests vendored patches by verifying the **committed artifact** (marked - `(vendored)` in the impact statement) — no install step needed. -- Re-running either form is idempotent. Patches dropped from `.socket/manifest.json` - are auto-reverted on the next `vendor` run; on a project vendored by - `scan --mode vendored`, use [`repair`](#repair) to verify or rebuild the committed - artifacts. - -**Examples:** -```bash -# Discover, download and vendor every patchable dependency (takes over hosted redirects) -socket-patch scan --mode vendored - -# Preview it (would_vendor / would_revendor / already_vendored) -socket-patch scan --json --mode vendored --dry-run - -# Vendor the agent-mode patches listed in .socket/manifest.json, -# or, in a hosted project with no manifest, eject its hosted pins -socket-patch vendor - -# Preview without writing anything -socket-patch vendor --dry-run - -# Then make it stick: commit .socket/ (vendor artifacts + ledger) and the lockfile -git add .socket package-lock.json && git commit -m "vendor Socket patches" - -# Undo everything (restores the original lockfile byte-for-byte; ejected hosted -# packages come back as their upstream registry entries) -socket-patch vendor --revert - -# JSON output for scripting -socket-patch vendor --json -``` - -### `list` - -List the patches in this project: the hosted pins your lockfiles wire (labeled -`Mode: hosted (wired in )` — JSON `details.mode: "hosted"` and -`details.lockfiles`), the vendor ledger's records (`Mode: vendored`), and any agent-mode -entries in `.socket/manifest.json`. A hosted pin shows its UUID only (hosted mode keeps no -local record; `vex` fetches it from the API), unless a pre-v5 -`.socket/vendor/redirect-state.json` still records it. A project with none prints `No -patches in this project. Run \`socket-patch scan\`.` and exits 0 (`--json`: the success -envelope with no events). - -**Usage:** -```bash -socket-patch list [options] -``` - -No command-specific options — see [Global options](#global-options) (`--json`, -`--manifest-path`, `--cwd` are the relevant ones). - -**Examples:** -```bash -# List patches socket-patch list - -# JSON output -socket-patch list --json -``` - -**Sample output:** -``` -Found 1 patch: - -Package: pkg:npm/flatted@3.3.1 - UUID: 5cac955f-eab1-4d29-8f4f-c408a6cc9647 - Mode: vendored (recorded in .socket/vendor/state.json) - Tier: free - License: MIT - Exported: Wed, 18 Mar 2026 22:53:26 GMT - Vulnerabilities (1): - - GHSA-25h7-pfq9-p65f (CVE-2026-32141) - Severity: HIGH - Summary: flatted vulnerable to unbounded recursion DoS in parse() revive phase - Files patched (6): - - package/cjs/index.js - - package/es.js - ... -``` - -### `get` - -Get one security patch from the Socket API and apply it. Accepts a UUID, CVE ID, GHSA -ID, PURL, or package name. The identifier type is auto-detected but can be forced with a -flag. Like `scan`, `get` defaults to hosted mode; pass `--mode vendored`, or -`--mode agent` for the manifest + in-place apply (implied by `--save-only` and -`--global`). When a package has -several patches, `get` picks the same one `scan` does (see -[Which patch is picked](#which-patch-is-picked)). Hosted and vendored `get` never -prompt, like `scan`; agent-mode `get` asks before applying (`--yes` or a non-TTY stdin -accepts). - -Alias: `download`. And as a shortcut, `socket-patch ` with a bare patch UUID is -rewritten to `socket-patch get `. - -**Usage:** -```bash -socket-patch get [options] -``` - -**Arguments:** -- `identifier` — patch UUID, CVE ID, GHSA ID, package PURL, or package name. Type is - auto-detected; force it with `--id` / `--cve` / `--ghsa` / `--package`. - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `--id` | — | Force identifier to be treated as a UUID. | -| `--cve` | — | Force identifier to be treated as a CVE ID. | -| `--ghsa` | — | Force identifier to be treated as a GHSA ID. | -| `-p, --package` | — | Force identifier to be treated as a package name. | -| `--save-only` | `SOCKET_SAVE_ONLY` | Download the patch without applying it (alias: `--no-apply`). | -| `--all-releases` | `SOCKET_ALL_RELEASES` | Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. | -| `--mode ` | — | How to consume the patch; the same modes as `scan --mode` (default: `agent`). | - -> Authenticated lookups run against an org. The slug is auto-resolved from your token -> when omitted; pass `--org ` (or set `SOCKET_ORG_SLUG`) to pick one explicitly — -> useful when the token belongs to multiple orgs. - -**Examples:** -```bash -# Get patch by UUID -socket-patch get 550e8400-e29b-41d4-a716-446655440000 - -# Get patch by CVE -socket-patch get CVE-2024-12345 - -# Get patch by GHSA -socket-patch get GHSA-xxxx-yyyy-zzzz - -# Get patch by package name (fuzzy matches installed packages) -socket-patch get lodash - -# Consume the patch in hosted mode (lockfile rewrite) instead of in place -socket-patch get CVE-2024-12345 --mode hosted - -# Download only, don't apply -socket-patch get CVE-2024-12345 --save-only - -# Apply to global packages -socket-patch get lodash -g - -# JSON output for scripting -socket-patch get CVE-2024-12345 --json -y -``` - -### `remove` - -Remove a patch from the manifest (rolls back files first by default). If the package is -[vendored](#vendor), `remove` also **reverts the vendoring** — the lockfile is restored -byte-for-byte and the `.socket/vendor/` artifact is deleted — so the patch is fully gone -in one command. Patches vendored by `scan --mode vendored` have no manifest entry and are -removable by PURL or UUID all the same (reverting the vendoring *is* the removal, so -`--skip-rollback` is refused for them). A hosted patch is removed the same way: its -lockfile entries are restored to their upstream registry entry, exactly as `rollback` -does it (refused, with the manifest untouched, where that is impossible). - -**Usage:** -```bash -socket-patch remove [options] -``` - -**Arguments:** -- `identifier` — package PURL (e.g. `pkg:npm/package@version`) or patch UUID. - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `--preserve-state` | `SOCKET_PRESERVE_STATE` | Restore the files and lockfiles but keep the patch's local state (manifest entry, vendored artifact + ledger entry) for a later re-apply, and skip blob cleanup — the single-patch twin of `rollback --preserve-state`. Conflicts with `--skip-rollback`. | -| `--skip-rollback` | `SOCKET_SKIP_ROLLBACK` | Only update the manifest, do not restore original files (for a vendored package that still has a manifest entry this also leaves the vendor wiring + artifact in place; refused for manifest-less vendored patches, where the revert *is* the removal). | - -**Examples:** -```bash -# Remove by PURL -socket-patch remove "pkg:npm/lodash@4.17.20" - -# Remove by UUID -socket-patch remove 550e8400-e29b-41d4-a716-446655440000 - -# Remove without rolling back files -socket-patch remove "pkg:npm/lodash@4.17.20" --skip-rollback - -# JSON output -socket-patch remove "pkg:npm/lodash@4.17.20" --json -``` - -### `rollback` - -Roll back patches to restore the system to unpatched. If no target is given, everything -is rolled back, across all three modes: in-place file restores (agent), vendored unwire + -artifact deletion + ledger-entry drop, and hosted lockfile entries restored to their -upstream registry entries. -The rolled-back entries are then removed from `.socket/manifest.json` (a zero-patch -`{"patches": {}}` husk stays) and their blobs are garbage-collected — a later `apply` has -nothing to re-apply. Pass `--preserve-state` to keep the local patch state (manifest -entries, vendored artifacts + ledger entries) for a later re-apply; use -[`remove`](#remove) for a single patch. - -**Hosted patches** are read from the lockfiles (hosted mode keeps no ledger). Each one is -rewritten back to the default upstream registry entry, with the tarball URL, integrity or -checksum re-resolved from the public registry — npm, crates.io, the Go module proxy, PyPI, -rubygems.org, packagist, nuget.org (Maven needs no network). Where that is impossible the -package is refused, nothing is written for it, and the run exits 1 with a hint to restore -the file from version control (`git checkout -- `): under `--offline`, when the -registry does not answer, for a binary `bun.lockb`, and for a few lock shapes whose -entries only the package manager can compute (see -[CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md), "Hosted unwind coverage"). -The registry bases honor the `SOCKET_NPM_REGISTRY`, `SOCKET_CRATES_INDEX`, -`SOCKET_GOPROXY`, `SOCKET_GOSUMDB_URL`, `SOCKET_PYPI_JSON_API`, `SOCKET_RUBYGEMS_URL`, -`SOCKET_PACKAGIST_URL` and `SOCKET_NUGET_URL` overrides for mirrors. A leftover pre-v5 -`.socket/vendor/redirect-state.json` is deleted once no lockfile pins a hosted patch. - -A wet run confirms once (auto-accepted under `--yes`/`--json`/non-TTY). Vendor-owned purls -the run did NOT act on (a corrupt vendor ledger) are listed in the JSON output's -`vendored` array; acted-on entries ride `vendoredReverted` / `vendoredPreserved` / -`vendoredKept`. - -**Usage:** -```bash -socket-patch rollback [targets]... [options] ``` -**Arguments:** -- `targets` — zero or more package PURLs, patch UUIDs or path globs (unioned). Omit to roll - back everything. - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `--preserve-state` | `SOCKET_PRESERVE_STATE` | Unpatch the system but keep the local patch state — manifest entries, vendored artifacts + ledger entries — for a later re-apply, and skip GC. Hosted patches have no preservable state (the lockfile is their only record) and are restored to upstream either way. | - -**Examples:** -```bash -# Rollback all patches -socket-patch rollback - -# Rollback a specific package -socket-patch rollback "pkg:npm/lodash@4.17.20" - -# Rollback by UUID -socket-patch rollback 550e8400-e29b-41d4-a716-446655440000 +Use your project's normal install command in place of `npm ci`. Some package +managers reuse installed or cached upstream packages; follow any reinstall warning +from the CLI and the [ecosystem notes](docs/ecosystems.md). Generate VEX after +installing to verify the copies your build consumes, then pass the document to your +VEX-aware vulnerability scanner. -# Dry run -socket-patch rollback --dry-run +## Patch modes -# JSON output -socket-patch rollback --json -``` - -### Agent mode +| Mode | Command | What to commit | What installs need | +| --- | --- | --- | --- | +| Hosted (default) | `socket-patch scan` | Changed lockfiles, manifests, and registry configuration | Access to Socket's patch server | +| Vendored | `socket-patch scan --mode vendored` | Changed dependency files and `.socket/vendor/` (artifacts and ledger) | The committed patched packages | +| Agent | `socket-patch scan --mode agent` | `.socket/manifest.json` and patch data; Go also uses a committed patched tree | `socket-patch apply` after dependency installs | -Agent mode keeps patches in `.socket/manifest.json` + `.socket/blobs/` and edits the -installed files in place, so the CLI has to run again after every install. `apply` -and `repair` are agent-mode commands; `get`, `list`, `remove` and `rollback` work in -every mode. +Vendored mode stores **patched dependencies**, not the entire dependency graph. +Other dependencies still need their normal registry, mirror, or offline cache. +Hosted and vendored installs do not need an install hook or the Socket Patch CLI. -### `apply` +The CLI supports npm, PyPI, Cargo, Go, RubyGems, Maven, Composer, NuGet, and Deno. +Mode and package-manager support vary: Deno uses agent mode, for example. Check the +[ecosystem support matrix](docs/ecosystems.md) before choosing a mode. -Apply the patches in `.socket/manifest.json` to the installed files in place. Idempotent — safe to run from install -hooks and CI on every build. +## Common commands -**Usage:** -```bash -socket-patch apply [options] +```sh +socket-patch scan --package lodash # limit selection to a package +socket-patch scan --max-new-patches 5 # introduce at most five new patches +socket-patch scan 'apps/*' # scan project directories in a monorepo +socket-patch get CVE-2024-12345 # target an advisory; hosted by default +socket-patch vendor # eject an existing hosted patch set +socket-patch rollback # restore upstream dependencies ``` -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `-f, --force` | `SOCKET_FORCE` | Skip pre-application hash verification (apply even if package version differs). | -| `--check` | — | Read-only audit that the committed **Go** `replace`-redirects match the manifest (for CI / GitHub-App auditing) — Go only, since cargo patches in place and has no redirect to audit. Lock-free, crawl-free, and offline-safe: exits 0 in sync, 1 on drift. Vendored modules are excluded from the audit. | -| `--vex ` | `SOCKET_VEX` | On a successful apply, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX generation](#inline-vex-on-apply--scan--vendor). | -| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. | - -**Examples:** -```bash -# Apply patches -socket-patch apply - -# Dry run -socket-patch apply --dry-run - -# Apply only npm patches -socket-patch apply --ecosystems npm - -# Apply in offline mode -socket-patch apply --offline - -# JSON output for CI/CD -socket-patch apply --json - -# Apply and emit an OpenVEX attestation in one step -socket-patch apply --vex socket.vex.json -``` - -> Packages managed by [`vendor`](#vendor) are skipped (`skipped`/`vendored` in JSON): the -> committed vendored artifact is the patch, so there is nothing for `apply` to do — even -> when the installed tree (e.g. `node_modules/`) is absent. - -### Agent mode in CI - -Agent mode patches the installed files in place, so every fresh dependency install -reverts the patches until `socket-patch apply` runs again. (Hosted and vendored projects -need no such step: the lockfile already names the patched packages.) Commit -`.socket/manifest.json` and its blobs, then run `apply` in CI after every install: - -```bash -# once, locally: record the patches (commit .socket/) -socket-patch scan --mode agent - -# in CI, after `npm ci` / `pip install` / `bundle install` / ... -socket-patch apply -``` - -> **v5.0: `setup` was removed.** See [Upgrading from `setup`](#upgrading-from-setup) to -> retire the install hooks it wrote. - -Per-ecosystem notes for in-place patching: - -- **Cargo** patches the crate in place (in `vendor/` or the registry cache, rewriting - `.cargo-checksum.json` so `cargo build` accepts it) — note that a non-vendored crate - patches the **shared** `$CARGO_HOME/registry` cache, which affects every project on - the machine and is silently reset by `cargo clean` or a cache prune; vendor the - dependency (`--mode vendored`) for a project-local, committable patch. -- **Go** writes a project-local patched copy under `.socket/go-patches/` plus a `go.mod` - `replace` directive (the module cache is `go.sum`-verified, so in-place patching can't - build); commit `go.mod` + `.socket/go-patches/` so a clone builds the patched bytes. -- **Maven / NuGet**: in-place patching leaves the caches' own checksum sidecars stale - (NuGet's fixup deletes `.nupkg.metadata` and raises an advisory for the signed-package - `.nupkg.sha512` marker; Maven's `.jar.sha1`/`.jar.md5` are left as-is) — the copy-out - modes, `scan --mode vendored` and `scan --mode hosted`, never touch the caches and - avoid the issue entirely. See - [ecosystems.md](docs/ecosystems.md#maven--nuget-caveats). -- **Deno** has no hosted or vendored mode, so agent mode is the only way to patch it. - -### Upgrading from `setup` - -v5 removes `socket-patch setup`. The hooks it wrote only ran `socket-patch apply`, so -they keep working until you delete them, but nothing maintains them any more. For each -project that ran `setup`: - -1. **Pick a mode.** - - *Move to hosted mode* (recommended; nothing runs after installs): run - `socket-patch rollback` (restores the patched files and empties the agent-mode - manifest), then `socket-patch scan`, and commit the lockfile changes and - `.socket/`. - - *Stay in agent mode*: keep `.socket/`, and add `socket-patch apply` to CI after - every install (see [Agent mode in CI](#agent-mode-in-ci)). -2. **Delete the hook for each ecosystem `setup` wired:** - - **npm / pnpm / yarn / bun**: in `package.json`, remove the - `npx @socketsecurity/socket-patch apply --silent --ecosystems npm` command (or its - `pnpm dlx` twin) from `scripts.postinstall`, and from `scripts.dependencies` if it - is there. Drop the script key if nothing else is left in it. - - **Composer**: in `composer.json`, remove - `socket-patch apply --offline --silent --ecosystems composer` from - `scripts.post-install-cmd` and `scripts.post-update-cmd`. - - **Python**: remove `socket-patch[hook]` from `requirements.txt`, or from - `[project].dependencies` / `[tool.poetry.dependencies]` in `pyproject.toml`, then - `pip uninstall socket-patch-hook` in each environment that has it. Those packages - no longer receive releases; install the CLI separately using the - [v5 installation methods](#installation). - - **Bundler**: delete the managed `plugin "socket-patch", path: ...` block from the - `Gemfile`, then `bundle plugin uninstall socket-patch`, and delete - `.socket/bundler-plugin/`, `.socket/gem-plugin-stamp` and the `/gem-plugin-stamp` - line in `.socket/.gitignore`. -3. **Check:** `socket-patch list` shows what remains. In agent mode, run - `socket-patch apply` once to confirm the manifest still applies. - -### `repair` - -Download missing blobs, re-vendor missing or corrupt vendored artifacts, and clean up unused -blobs. - -Alias: `gc` - -`repair` cleans up the `.socket/` directory without running a scan — useful when you've -manually adjusted the manifest, recovered from a partial-failure state, or just want to -free space. It also re-vendors missing or corrupt vendored artifacts the same way `vendor` -does (the patch service's prebuilt artifact first, a local build as the fallback), checked -against `.socket/vendor/state.json`. `repair` does not recreate a lost `state.json`: if a -lockfile points into `.socket/vendor/` and the ledger has no entry for it, `repair` fails with -`vendor_ledger_missing` — restore `state.json` from version control. For the combined -agent-mode workflow (discover + apply + GC in one pass), use `scan --sync` instead. - -Like every other mutating command, `repair` takes the `.socket/apply.lock` advisory lock -while it runs and removes it when it finishes. If another `socket-patch` process is -actively running, `repair` refuses up front with `lock_held` (exit 1); it never steals a -live lock — wait for the other process to finish, or budget a wait with `--lock-timeout`. - -**Usage:** -```bash -socket-patch repair [options] -``` - -**Command-specific options** (plus all [Global options](#global-options)): -| Flag | Env var | Description | -|------|---------|-------------| -| `--download-only` | `SOCKET_DOWNLOAD_ONLY` | Only download missing artifacts, do not clean up (incompatible with `--offline`). | - -**Examples:** -```bash -# Full repair (download missing + clean up unused) -socket-patch repair - -# Cleanup only — missing blobs are warned about and skipped, never downloaded -socket-patch repair --offline - -# Download missing blobs only -socket-patch repair --download-only - -# JSON output for scripting -socket-patch repair --json -``` - -## OpenVEX attestations - -`socket-patch vex` turns the patches your project carries into a machine-readable statement of *which -known vulnerabilities no longer affect your build* because a Socket patch has been applied. -This lets vulnerability scanners stop flagging CVEs that you've already remediated in -place — without bumping the package version. - -**How it works** - -1. Gathers every patch the project can prove: agent-mode patches from - `.socket/manifest.json`, and [vendored](#vendor) / [hosted](#three-patch-modes) patches - from the wiring in your **lockfiles** (plus the vendor ledger when it is committed; - hosted records are fetched from the API). See [No manifest needed for hosted and vendored - patches](#no-manifest-needed-for-hosted-and-vendored-patches). -2. Unless `--no-verify` is passed, re-checks each patch's bytes so the attestation only - covers patches that are actually applied: agent patches against the installed tree, - vendored patches against the **committed artifact** (marker `(vendored)`), and hosted - patches against the installed copy the build consumes — or, before any install, against - the lockfile's integrity pin (marker `(redirected)`). Whatever `--no-verify` says, a record the - lockfile no longer wires is never attested. -3. Auto-detects the top-level **product** identifier (override with `--product`), probing - in order: - - `.git/config` `[remote "origin"]` → `pkg:github//` (similar for - GitLab/Bitbucket; raw URL otherwise) - - `package.json` → `pkg:npm/@` - - `pyproject.toml` → `pkg:pypi/@` - - `Cargo.toml` → `pkg:cargo/@` - - `go.mod` → `pkg:golang/` - - `composer.json` → `pkg:composer//[@]` - - `pom.xml` → `pkg:maven//[@]` - - the root's single `*.csproj` → `pkg:nuget/[@]` - - the root's single `*.gemspec` → `pkg:gem/[@]` -4. Emits an OpenVEX 0.2.0 document whose statements mark each mitigated vulnerability as - `not_affected` (justification: the patch is present), suitable for piping into - `vexctl`, Grype, Trivy, and similar tools. - -**Provenance markers** - -Each statement's impact string records *how* the patch is persisted — one marker per -[patch mode](#three-patch-modes): - -| Impact statement | Mode | What the evidence is | What a consumer should do | -|---|---|---|---| -| `Patched via Socket patch ` | agent | The installed tree: every patched file's hash was verified against the manifest's `afterHash` | Trust the statement as long as a CI `apply` keeps re-applying after every install | -| `Patched via Socket patch (vendored)` | vendored | The **committed** `.socket/vendor/` artifact was hash-verified — no install hook needed; the lockfile wiring is the persistence mechanism | Trust it on any checkout; the committed bytes are the patch | -| `Patched via Socket patch (redirected)` | hosted | The lockfile's integrity pin points at the Socket-hosted patched package. A post-install `socket-patch vex` hash-verifies the installed copy; before any install it attests from the pin. When emitted in-run by a hosted `scan --vex`, the statement is attested **without hash verification** (the bytes are fetched at install time — the JSON `vex` summary carries `verified: false`) | Ensure installs still resolve from `patch.socket.dev` (the lockfile edit is intact), and run `socket-patch vex` **after installing** to have the redirected patches hash-verified against the installed tree | - -The markers are stable strings (see -[CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md)); scanners and policy engines -may match on them. - -**Output channels** - -| Invocation | VEX document | Status / summary | -|------------|--------------|------------------| -| _default_ (no `--output`, no `--json`) | stdout | one-line summary (stderr) | -| `--output ` | the file | one-line summary (stdout) | -| `--json --output ` | the file | machine-readable envelope on stdout (the CI shape) | - -`--json` requires `--output`, since the VEX document is itself JSON and would otherwise -collide with the envelope on stdout. - -**Using it with a scanner** - -```bash -# Generate the attestation as part of CI, then hand it to a scanner -socket-patch vex --output socket.vex.json - -# Suppress already-patched findings in Grype -grype --vex socket.vex.json - -# Or with Trivy -trivy image --vex socket.vex.json -``` - -Patch first (in any mode). When nothing names a patch anywhere — no manifest -entry, no vendor ledger entry, no hosted or vendored lockfile reference — `vex` -errors with `no_patches` (exit 1) when the manifest file exists but is empty, or with -`manifest_not_found` (exit 2) when there is no manifest either. When there are patches but -none can be attested, it exits 1 with `no_applicable_patches`, and each omission is listed -with its reason: `hash_mismatch`, `record_unavailable`, `redirect_unwired`, and so on. - -### No manifest needed for hosted and vendored patches - -A hosted or vendored checkout needs no `.socket/manifest.json`, and no vendor ledger -either. This covers a depscan-opened PR, a clone of a repo that never committed its -vendor ledger, and every hosted project (hosted mode keeps no ledger at all). `vex` reads -the patch reference out of each root lockfile or config: a `patch.socket.dev` URL (or one -on your `--patch-server-url`) or a `.socket/vendor///…` path carries the patch -uuid. It then finds that patch's record in the manifest or vendor ledger, or fetches it -from the patch API — the normal path for hosted patches. The references it accepts are what socket-patch's own -rewriters write: a URL on any other host, or an entry the package manager would not -install from, is ignored. - -```bash -# Fresh clone of a hosted or vendored project: nothing installed, no .socket/manifest.json -socket-patch vex --output socket.vex.json -``` - -Behavior worth knowing: - -- **Network.** Without a local record, `vex` fetches the patch by uuid from the patch API. - With `--offline`, or when the fetch fails or the patch is paid and not entitled, the patch - is omitted as `record_unavailable`. Hosted patches therefore need the network to be - attested; commit the vendor ledger, or keep the manifest, to attest offline. -- **Liveness.** A vendor ledger entry (or a leftover pre-v5 hosted record) attests only - while a lockfile still wires it. Otherwise it is omitted as `vendor_unwired` or - `redirect_unwired`, even under `--no-verify`. Lockfiles - that wire one package to different patches (`wiring_conflict`) attest none of them. A - package that one lock wires to a patch while another lock resolves it from the registry - is not attested either. -- **Diagnostics.** A lockfile that cannot be read or parsed, or a Socket reference that - fails validation, is reported as a warning (`lockfile_unparseable`, `patched_ref_invalid`, - …) and never aborts the run. With `--json` these go in `warnings[]`. -- **Scope.** Only the project root is read (plus Rush's `common/config` pnpm locks). Nested - workspace-member lockfiles are not. - -| Ecosystem | Files read (project root) | Limitations | -|---|---|---| -| npm | `package-lock.json`, `npm-shrinkwrap.json` (both) | `link` / bundled entries never count | -| pnpm | `pnpm-lock.yaml` (all generations), `shrinkwrap.yaml` (pnpm 1/2), Rush locks | Aliased / nested `resolution` shapes are diagnosed, not attested; `overrides` alone prove nothing | -| yarn | `yarn.lock` (classic + berry) | Berry vendored entries also need the root `package.json` `resolutions` mapping; member locks are not read | -| bun | `bun.lock`, else `bun.lockb` | A hosted entry that Bun < 1.3.10 re-saved without its sha512 attests only after install | -| vlt | `vlt-lock.json` (`lockfileVersion` absent, 0 or 1) | A BOM-prefixed or other-version lock wires nothing; a same-version instance on another registry keeps a hosted pin from attesting before install; a vendored directory whose `package.json` patch lost its devDependencies needs the patched blob in `.socket/blobs` without the vendor ledger | -| cargo | `Cargo.lock`, `Cargo.toml`, `.cargo/config[.toml]` | Root manifest + project config only (no `$CARGO_HOME` / parent configs); vendored `[patch.crates-io]` entries are read from `Cargo.toml` first (v5), the project config for pre-v5 projects, and must agree with the detached lock entry's tagged version `+socket.` (a tag for another uuid — in the lock or in the copy's own `Cargo.toml` — is dead wiring; an untagged detached entry counts only beside an untagged, pre-tag copy); a manifest entry cargo ignores (a same-key project-config item, or a URL-spelled crates.io `[patch]` table) is not attested; a lockless hosted pin (no `Cargo.lock`) names no version and is not attested — nor seen by `list` / `rollback` (only a pre-v5 redirect ledger record keeps it live) | -| golang | `go.mod`, `go.work`, `go.sum`, `go.work.sum` | A replace that `require` no longer selects is inert; `vendor/modules.txt` is not read | -| pypi | `uv.lock`, `*.py.lock`, `pylock*.toml`, `poetry.lock`, `pdm.lock`, `Pipfile.lock`, `requirements.txt` (+ `-r` includes), `pyproject.toml` / `hatch.toml` | A `uv.lock` beside a `pyproject.toml` must agree with its `[tool.uv.sources]`; PDM 3.1 / 4.0–4.2 locks are refused; a Pipenv project needs `--product` (or a git remote) | -| gem | `Gemfile.lock`, `gems.locked` | Platform gems unsupported; a Gemfile-only (pre-bundler-2.6, not yet locked) wiring is not attested — nor seen by `list` / `rollback` (only a pre-v5 redirect ledger record keeps it live) | -| composer | `composer.lock` | `installed.json` and `COMPOSER=`-renamed locks are not read | -| maven | `pom.xml` (+ `.mvn/` checksums) | Root pom only (no parents / submodules, no Gradle); legacy same-GAV hosted repositories cannot be attributed | -| nuget | `nuget.config`, `packages.lock.json` | Hosted needs a `packages.lock.json` entry for the id: with no lock, the mapping names no version and is not attested — nor seen by `list` / `rollback` (only a pre-v5 redirect ledger record keeps it live); root config only | -| deno | none | No hosted or vendored mode exists; Deno patches attest only through the manifest (agent mode) | - -The full recognition rules are in -[CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md) ("Manifest-less VEX"). - -### Inline VEX on `apply` / `scan` / `vendor` - -You don't need a separate `vex` invocation: pass `--vex ` to `apply`, `scan`, or -`vendor` and the same OpenVEX document is generated as a side-effect of a successful run. - -```bash -# Hosted scan and attest in one step (not hash-verified until installed: re-run `vex` then) -socket-patch scan --vex socket.vex.json - -# Vendor and attest — manifest-less by construction -socket-patch scan --json --mode vendored --vex socket.vex.json - -# Agent mode: patch in place and attest -socket-patch apply --vex socket.vex.json -socket-patch scan --json --sync --vex socket.vex.json -``` - -The `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, and `--vex-compact` flags mirror -the standalone command's `--product` / `--no-verify` / `--doc-id` / `--compact` knobs. - -Contract: - -- The document is **always written to the file** (never stdout), so it never collides - with the command's own `--json` output. JSON mode adds a top-level `vex` summary — - `{ path, statements, format }` — to the envelope (`apply`) / result (`scan`). -- It's built from the project **as it stands after the run** — the manifest (including - any `--mode agent` writes), the vendor ledger, and the lockfile wiring — and - verified against on-disk state unless `--vex-no-verify` is set. Generated for real runs - and report-only scans alike; `--dry-run` skips it (nothing was changed, so nothing is - attested). -- `apply --vex` and `vendor --vex` with **no manifest** still attest what the lockfiles and - the vendor ledger wire. A project with nothing wired anywhere keeps the calm exit 0 and writes no - document. `apply --check` never generates one. -- **Fail-the-command:** if `--vex` was requested but generation fails (no detectable - product, nothing attestable, a corrupt vendor ledger, unwritable path), the command exits - non-zero **even when the apply/scan itself succeeded**, with a stable error code in the - JSON output. - -## Scripting & CI/CD - -All commands support `--json` for machine-readable output. JSON responses always include -a `"status"` field for easy error detection. - -**Authentication in CI:** a runner has no `socket login` state — if your organization -has org-tier patches, provide the token as a CI secret via `SOCKET_API_TOKEN` (without -it, runs silently fall back to the anonymous public proxy and see free patches only, and -paid-tier blob downloads report `paidRequired`). To deliberately pin a run to the -anonymous free tier, set `SOCKET_NO_API_TOKEN=1`. See -[Configuration sources](#configuration-sources). - -```bash -# Read-only check: what would a hosted scan patch? (writes nothing) -result=$(socket-patch scan --json --dry-run --ecosystems npm) -echo "$result" | jq '{patches: .totalPatches, redirected: .redirect.redirected, updates: (.updates | length)}' - -# Auto-update bot (hosted): take new and newer patches, then let the PR action commit -socket-patch scan --json | jq '{redirected: .redirect.redirected, files: .redirect.rewrittenFiles}' -# The PR action (e.g. peter-evans/create-pull-request) commits the working-tree -# changes (lockfiles + .socket/vendor/); use this summary as the PR body. - -# Agent-mode bot: discover, apply, and garbage-collect in one pass -socket-patch scan --json --sync | jq '{ - applied: [.apply.patches[]? | select(.action == "added" or .action == "updated") | .purl], - pruned: (.gc.prunedManifestEntries // []), - bytes_freed: (.gc.bytesFreed // 0) -}' - -# Agent mode: re-apply committed patches and check the result -socket-patch apply --json | jq '.status' -# "success", "partialFailure", "noManifest", or "error" -``` - -`scan` and hosted/vendored `get` never prompt, so CI needs no `--yes` for them. The -commands that do confirm (agent-mode `get`, `rollback`, `remove`) auto-proceed when stdin is not a TTY. Progress -indicators and ANSI colors are automatically suppressed when output is piped. - -The exact JSON shapes, exit codes, and stability guarantees are specified in -[CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md). - -## Manifest format - -Agent mode records downloaded patches in `.socket/manifest.json` (hosted and vendored -mode never write it): - -```json -{ - "patches": { - "pkg:npm/package-name@1.0.0": { - "uuid": "unique-patch-id", - "exportedAt": "2024-01-01T00:00:00Z", - "files": { - "path/to/file.js": { - "beforeHash": "git-sha256-before", - "afterHash": "git-sha256-after" - } - }, - "vulnerabilities": { - "GHSA-xxxx-xxxx-xxxx": { - "cves": ["CVE-2024-12345"], - "summary": "Vulnerability summary", - "severity": "high", - "description": "Detailed description" - } - }, - "description": "Patch description", - "license": "MIT", - "tier": "free" - } - } -} -``` +`get` also accepts a GHSA, patch UUID, PURL, or package name. `scan` selects from +patches your account can download, preferring the newest merged patch and then the +highest-severity patch. Existing patches are upgraded only by a better-ranked patch. -Patched file contents are in `.socket/blobs/` (named by git SHA256 hash). +Hosted rollback resolves upstream metadata and generally needs network access. +Where restoration is unsupported, including hosted binary `bun.lockb`, the CLI +refuses the change and gives a version-control recovery hint. See +[usage and recovery](docs/usage.md). -A manifest written by an earlier release may also carry a top-level `"setup"` key -(`manual`, `exclude`) from the removed `setup` command; v5 keeps it on rewrite but -ignores it. +Use `socket-patch --help` for options and +[`socket.yml`](docs/configuration.md#repository-patch-policy) for a shared rollout policy. -## Further reading +## Documentation -- **[Ecosystem & platform support](docs/ecosystems.md)** — the full mode × ecosystem - matrix, per-ecosystem caveats (Maven, NuGet, Rush monorepos, Go), and supported - platforms. -- **[CLI contract](crates/socket-patch-cli/CLI_CONTRACT.md)** — the machine-readable - surface: exact JSON shapes, exit codes, flag/env bindings, and the semver policy that - governs them. -- **[Design notes](docs/design/)** — e.g. [the configuration model](docs/design/configuration.md) - and [hosted mode for Go](docs/design/golang-hosted.md) (free tier; the - [paid-tier no-go analysis](docs/design/golang-hosted-no-go.md) it supersedes). -- **[Changelog](CHANGELOG.md)** +- [Usage](docs/usage.md): targeting, CI, vendoring, agent mode, VEX, and recovery. +- [Configuration](docs/configuration.md): authentication, environment, and rollout policy. +- [Ecosystem support](docs/ecosystems.md): package-manager formats and limitations. +- [Migrating to v5](docs/migrating-to-v5.md): changed defaults and retired install hooks. +- [CLI contract](crates/socket-patch-cli/CLI_CONTRACT.md): flags, JSON, diagnostics, and exit codes. +- [Development](docs/development.md): code map, builds, and test entry points. +- [Release runbook](docs/releasing.md) and [changelog](CHANGELOG.md). diff --git a/crates/socket-patch-cli/CLI_CONTRACT.md b/crates/socket-patch-cli/CLI_CONTRACT.md index 70f217f79..0a6c90b53 100644 --- a/crates/socket-patch-cli/CLI_CONTRACT.md +++ b/crates/socket-patch-cli/CLI_CONTRACT.md @@ -1,9 +1,17 @@ # socket-patch CLI contract -This document defines the **public surface** of the `socket-patch` binary. Anything listed here is part of the user-visible contract: third-party scripts, CI pipelines, and the npm/pypi/cargo wrappers depend on it. Changes are governed by the semver policy at the bottom of this file. +This document defines the **public surface** of the `socket-patch` binary. Third-party scripts, CI pipelines, and the npm distribution depend on this contract. Changes are governed by the semver policy at the bottom of this file. > **Why this exists.** A flag rename, a default-value change, or a JSON key rename can land green and break every shipped wrapper silently. The contract below is backed by the unit tests under `crates/socket-patch-cli/src/**` (`#[cfg(test)] mod tests`) and the parser tests under `crates/socket-patch-cli/tests/cli_parse_*.rs`. Changes that violate the contract must update those tests in lock-step with a major version bump. +For task-oriented guidance, start with [usage](../../docs/usage.md), +[configuration](../../docs/configuration.md), or [v5 migration](../../docs/migrating-to-v5.md). + +**Reference:** [Commands](#subcommands) · [Arguments](#global-arguments) · +[Policy](#socketyml-patch-policy-v50) · [VEX](#manifest-less-vex-lockfile-discovery) · +[Vendoring](#vendor-command-contract) · [Rollback](#rollback-command-contract-v50) · +[Environment](#environment-variables) · [JSON](#json-output-shapes) · [Exit codes](#exit-codes) + ## Subcommands | Name | Visible alias(es) | Notes | @@ -12,11 +20,11 @@ This document defines the **public surface** of the `socket-patch` binary. Anyth | `vex` | — | Emit an OpenVEX 0.2.0 attestation derived from the local manifest, the vendor ledger, and the hosted / vendored patch references the project's lockfiles wire (no manifest required; hosted records come from the API) | | `vendor` | — | Eject patched dependencies into committable `.socket/vendor/` and rewire lockfiles | | `list` | — | Print patches in the local manifest, plus the vendor ledger's records (v5.0) and the hosted pins the lockfiles wire (labeled; see the action matrix; an empty project exits 0) | -| `get` | `download` | Agent mode by default (`--mode` selects hosted/vendored): fetch + apply a patch; requires positional `identifier` | +| `get` | `download` | Fetch a selected patch in hosted mode by default; `--mode agent` selects in-place application, also the default with `--save-only` or global targeting. Requires positional `identifier`. | | `apply` | — | Agent mode: apply patches from the local manifest | | `rollback` | — | **Full-state rollback (v5.0, MAJOR)**: restore original files AND unwind vendored lockfile wiring / restore hosted pins to their upstream registry entries, remove the rolled-back entries from the manifest, and GC their blobs/archives; takes optional variadic positional `targets` (PURL \| UUID \| path glob). See [Rollback command contract](#rollback-command-contract-v50) | -| `remove` | — | Agent mode: remove a patch from manifest (rolls back first); requires positional `identifier` | -| `repair` | `gc` | Agent mode: download missing blobs, re-vendor missing/corrupt vendored artifacts (never re-synthesizing a lost ledger), and clean up unused ones (refuses with `lock_held` when a live process holds the lock; see "Lock lifecycle" below) | +| `remove` | — | Restore and remove one patch across hosted, vendored, and agent state; requires positional `identifier`. | +| `repair` | `gc` | Download missing agent blobs, re-vendor missing/corrupt vendored artifacts (never re-synthesizing a lost ledger), and clean up unused ones (refuses with `lock_held` when a live process holds the lock; see "Lock lifecycle" below) | Rows are in `--help` order (v5.0): the hosted/vendored workflow (`scan` → `vex` → `vendor`, with `list` to inspect), then the agent-mode (in-place patching) commands. @@ -34,7 +42,7 @@ Rows are in `--help` order (v5.0): the hosted/vendored workflow (`scan` → `vex ## Global arguments -In v3.0 every subcommand accepts the same set of "global" flags via a single shared `GlobalArgs` struct that's `#[command(flatten)]`-ed into each per-command struct (`crates/socket-patch-cli/src/args.rs`). Subcommands that don't actually consume a given flag accept it silently — e.g. `list --global` parses fine and is a no-op. Every flag also has an environment-variable binding; precedence is **CLI arg > env var > default** — and for exactly three keys (`--api-token`, `--org`, `--api-url`) the JS socket-cli's persisted login sits between env var and default: **CLI arg > env var (canonical, then `SOCKET_CLI_*` alias) > socket-cli `config.json` > default**. See "Persisted configuration" under Environment variables. +Every subcommand accepts the same set of "global" flags via a single shared `GlobalArgs` struct that's `#[command(flatten)]`-ed into each per-command struct (`crates/socket-patch-cli/src/args.rs`). Subcommands that don't actually consume a given flag accept it silently — e.g. `list --global` parses fine and is a no-op. Every flag also has an environment-variable binding; precedence is **CLI arg > env var > default** — and for exactly three keys (`--api-token`, `--org`, `--api-url`) the JS socket-cli's persisted login sits between env var and default: **CLI arg > env var (canonical, then `SOCKET_CLI_*` alias) > socket-cli `config.json` > default**. See "Persisted configuration" under Environment variables. | Long | Short | Env var | Default | Type | Semantic | |---|---|---|---|---|---| @@ -180,7 +188,7 @@ The hidden alias `--no-apply` on `get --save-only` is **part of the contract** ### socket.yml patch policy (v5.0) -A repository can **narrow** what `scan` patches with a `patches` block in its root `socket.yml` (the Socket scanner's config file; `version: 2` keeps every other consumer working — they strip or ignore the block). Design record: `docs/design/staged-rollout.md`. +A repository can **narrow** what `scan` patches with a `patches` block in its root `socket.yml` (the Socket scanner's config file; `version: 2` keeps every other consumer working — they strip or ignore the block). Usage guide: [repository patch policy](../../docs/configuration.md#repository-patch-policy). **Grammar.** Every key is optional; camelCase, like the rest of socket.yml. @@ -261,9 +269,9 @@ patches: ### Per-run limit on new patches (`scan --max-new-patches`, v5.0) -`scan --max-new-patches ` (env `SOCKET_MAX_NEW_PATCHES`; socket.yml `patches.maxNewPatches`) paces a rollout: each run adds at most N patches to packages that had none, the most critical first, and defers the rest to the next run. It applies to `scan` in hosted, vendored and agent mode, wet and `--dry-run`, and to the in-memory engine (napi `maxNewPatches`, `hosted-bundle`); `get` is explicit intent and ignores it. Design: `docs/design/staged-rollout.md` §5. +`scan --max-new-patches ` (env `SOCKET_MAX_NEW_PATCHES`; socket.yml `patches.maxNewPatches`) paces a rollout: each run adds at most N patches to packages that had none, the most critical first, and defers the rest to the next run. It applies to `scan` in hosted, vendored and agent mode, wet and `--dry-run`, and to the in-memory engine (napi `maxNewPatches`, `hosted-bundle`); `get` is explicit intent and ignores it. Usage guide: [gradual rollout](../../docs/configuration.md#gradual-rollout). -**Classification.** After per-package selection, each selected `(project, purl)` row is compared with the project's **recorded view** — the merged manifest > hosted lockfile pins > vendor ledger that `updates[]` reads (§5.1): +**Classification.** After per-package selection, each selected `(project, purl)` row is compared with the project's **recorded view** — the merged manifest > hosted lockfile pins > vendor ledger that `updates[]` reads: | Class | Rule | Capped | The writer gets | |---|---|---|---| @@ -422,7 +430,7 @@ hand (the `postinstall`/`dependencies` entries, the `socket-patch[hook]` depende `socket-patch-bundler` gem are no longer published. Prefer hosted or vendored mode: their lockfile (and `.socket/vendor/`) edits are the persistence, so -no install step exists. Agent mode (`scan --mode agent`, `get`, `apply`) patches the installed tree +no Socket Patch install hook is needed. Agent mode (`scan --mode agent`, `get --mode agent`, `apply`) patches the installed tree in place, which the next package-manager install reverts; wire it into CI yourself: ```sh @@ -1023,7 +1031,7 @@ State lives at `$XDG_CACHE_HOME`|`~/.cache` (Unix/macOS) or `%LOCALAPPDATA%` (Wi ## Environment variables -All v3.0 env vars use the `SOCKET_*` prefix. Three legacy `SOCKET_PATCH_*` names are still honored at runtime for compatibility: on first read of any of the three the binary emits a one-shot deprecation warning to stderr (the warning fires unconditionally — even under `--silent` / `--json` — because it's a transition signal users need to see). The legacy names will be removed in a future major release. +Public configuration uses the `SOCKET_*` names below. The three deprecated v3/v4 environment aliases were removed in v5; see [Removed env vars](#removed-env-vars). Four `SOCKET_CLI_*` names from the sibling JS Socket CLI are additionally accepted as **peer aliases** (supported, not deprecated — no warning): `SOCKET_CLI_API_TOKEN` → `SOCKET_API_TOKEN`, `SOCKET_CLI_ORG_SLUG` → `SOCKET_ORG_SLUG`, `SOCKET_CLI_API_BASE_URL` → `SOCKET_API_URL`, `SOCKET_CLI_NO_API_TOKEN` → `SOCKET_NO_API_TOKEN`. The canonical `SOCKET_*` name always wins when both are set; promotion is silent and happens in-process before clap parses. Other socket-cli names (`SOCKET_CLI_CONFIG`, `SOCKET_CLI_API_PROXY`, `SOCKET_CLI_DEBUG`) are deliberately **not** honored. @@ -1058,7 +1066,7 @@ Empty string means unset at every layer: exported-but-empty flag-bound vars are | `SOCKET_NO_NPM_ALLOW_REMOTE_CONFIG` | `--no-npm-allow-remote-config` | `false` | Hosted mode: skip the `allow-remote=all` write to the project `.npmrc`. | | `SOCKET_NO_VLT_INSTALL_CLEANUP` | `--no-vlt-install-cleanup` | `false` | Hosted mode, `rollback`, `remove`: keep stale vlt installed copies. | | `SOCKET_FORCE` | `apply --force` / `-f`, `vendor --force` / `-f`, `--update --force` | `false` | Local to `apply`, `vendor` and `--update`. | -| `SOCKET_PATCH_VERSION` | `--update ` | (latest) | Local to `--update`; the same pin `install.sh` and the gem launcher honor. | +| `SOCKET_PATCH_VERSION` | `--update ` | (latest) | Local to `--update`; the same pin `install.sh` honors. | | `SOCKET_BATCH_SIZE` | `scan --batch-size` | `500` authenticated / `100` proxy | Local to `scan`. | | `SOCKET_MAX_NEW_PATCHES` | `scan --max-new-patches` | (unlimited) | Local to `scan` (v5.0): a count or `none`; empty is unset, malformed exits 2. | | `SOCKET_SCAN_PACKAGES` | `scan --package` | (none) | Local to `scan` (v5.0); comma-separated names or purls. | diff --git a/crates/socket-patch-cli/src/commands/scan/rollout.rs b/crates/socket-patch-cli/src/commands/scan/rollout.rs index 8c7042f7b..82ef99e17 100644 --- a/crates/socket-patch-cli/src/commands/scan/rollout.rs +++ b/crates/socket-patch-cli/src/commands/scan/rollout.rs @@ -1,5 +1,5 @@ -//! Scan's side of the rollout stage (`docs/design/staged-rollout.md` §5, -//! §9.2): `updates[]`, the hosted gate and the human lines. The stage +//! Scan's side of the rollout stage (`docs/configuration.md#gradual-rollout`): +//! `updates[]`, the hosted gate and the human lines. The stage //! itself is [`socket_patch_core::rollout::stage`]. use std::collections::{BTreeMap, BTreeSet, HashSet}; diff --git a/crates/socket-patch-cli/src/commands/scan/rollout_args.rs b/crates/socket-patch-cli/src/commands/scan/rollout_args.rs index 47b7b7ca5..e4d251e98 100644 --- a/crates/socket-patch-cli/src/commands/scan/rollout_args.rs +++ b/crates/socket-patch-cli/src/commands/scan/rollout_args.rs @@ -1,5 +1,5 @@ -//! `scan --max-new-patches` (work item B of the staged-rollout design, -//! `docs/design/staged-rollout.md` §5). +//! `scan --max-new-patches` (see the rollout guide, +//! `docs/configuration.md#gradual-rollout`). use clap::Args; diff --git a/crates/socket-patch-cli/tests/e2e_golang_hosted_build.rs b/crates/socket-patch-cli/tests/e2e_golang_hosted_build.rs index 59a96a70d..6adcb5a7a 100644 --- a/crates/socket-patch-cli/tests/e2e_golang_hosted_build.rs +++ b/crates/socket-patch-cli/tests/e2e_golang_hosted_build.rs @@ -6,7 +6,7 @@ //! machinery still has teeth against a tampered pin. //! //! The three properties this pins (each validated empirically before the -//! feature was built — see `docs/design/golang-hosted.md`): +//! feature was built — see `docs/ecosystems.md#go-directory-replaces-and-gosum`): //! //! 1. **No sumdb consultation**: `GOSUMDB` is set to a bogus database name //! for every day-2 command. go parses `GOSUMDB` lazily and consults it only diff --git a/crates/socket-patch-cli/tests/e2e_hosted_production.rs b/crates/socket-patch-cli/tests/e2e_hosted_production.rs index be8b9b90c..89384e9a4 100644 --- a/crates/socket-patch-cli/tests/e2e_hosted_production.rs +++ b/crates/socket-patch-cli/tests/e2e_hosted_production.rs @@ -51,7 +51,7 @@ //! cargo tier emptied on 2026-08-28, so the leg was demoted to the canary //! (`docs/testing/hosted-production-e2e.md` says how to re-promote it). //! * **golang** — hosted mode is supported for free-tier references carrying -//! a `goproxy` override (`docs/design/golang-hosted.md`), but production +//! a `goproxy` override (`docs/ecosystems.md#go-directory-replaces-and-gosum`), but production //! publishes no golang hosted modules yet. Covered as a shape guard that //! holds in both worlds. //! * **deno** — hosted mode is not supported. Covered as a negative assertion. @@ -2427,7 +2427,7 @@ fn statements_for_opt(doc: Option<&serde_json::Value>, purl: &str) -> usize { // =========================================================================== /// Go hosted mode: supported for free-tier references that carry a `goproxy` -/// override (`docs/design/golang-hosted.md`); refused with +/// override (`docs/ecosystems.md#go-directory-replaces-and-gosum`); refused with /// `redirect_golang_unsupported` otherwise (`golang-hosted-no-go.md`, the /// paid-tier analysis). /// diff --git a/crates/socket-patch-cli/tests/e2e_redirect_gem_build.rs b/crates/socket-patch-cli/tests/e2e_redirect_gem_build.rs index 5ba18f3e6..28191bbf0 100644 --- a/crates/socket-patch-cli/tests/e2e_redirect_gem_build.rs +++ b/crates/socket-patch-cli/tests/e2e_redirect_gem_build.rs @@ -6,7 +6,7 @@ //! `/api/v1/dependencies` fallback returned a zero-byte body); the 2026-08-18 //! gem catalog republish fixed the served index, and this hermetic suite pins //! the contract from both sides regardless of production's current state — -//! see the history section of `docs/testing/hosted-production-e2e.md`. +//! see `docs/testing/hosted-production-e2e.md` for the live-service counterpart. //! //! Unlike the npm/cargo siblings, this suite is FULLY hermetic: the fixture //! gems are authored here and built with the real `gem build`, and ONE @@ -1390,8 +1390,8 @@ async fn gem_hosted_gems_rb_spelling_redirects_and_installs() { /// The compact-index DEPENDENCY contract, pinned from the red side: a patch /// registry whose `/info` omits the gem's runtime deps (production's -/// HISTORICAL behavior until the 2026-08-18 republish fixed the served index -/// — see docs/testing/hosted-production-e2e.md's history section) BREAKS the +/// HISTORICAL behavior until the 2026-08-18 republish fixed the served index) +/// BREAKS the /// prescribed install with bundler's `APIResponseMismatchError`. If the CLI /// or fixture ever starts tolerating that silently, this turns red. #[tokio::test(flavor = "multi_thread")] diff --git a/crates/socket-patch-core/README.md b/crates/socket-patch-core/README.md index ebb97ad4d..594d15dac 100644 --- a/crates/socket-patch-core/README.md +++ b/crates/socket-patch-core/README.md @@ -4,11 +4,15 @@ Core library for [socket-patch](https://github.com/SocketDev/socket-patch) — a ## What this crate provides -- **Manifest management** — read, write, and validate `.socket/manifest.json` patch manifests -- **Patch engine** — apply and rollback file-level patches using git SHA-256 content hashes -- **Crawlers** — discover installed packages across npm, PyPI, Ruby gems, Cargo, Go, Maven, Composer, NuGet, and Deno -- **API client** — fetch patches from the Socket API -- **Utilities** — PURL parsing, blob storage, hash verification, fuzzy matching +- Dependency discovery from installed packages and lockfiles. +- Hosted dependency rewriting, including the in-memory engine used by the Node bindings. +- Selection policy and gradual rollout shared across disk and in-memory scans. +- Vendored artifact acquisition, verification, wiring, and reversal. +- Agent patch manifests and file-level apply/rollback with content-hash checks. +- Socket API access and OpenVEX generation from patch records and live references. + +See the repository's [development guide](../../docs/development.md) for the code map +and [ecosystem matrix](../../docs/ecosystems.md) for supported formats and limits. ## Usage diff --git a/crates/socket-patch-core/src/patch/redirect/mod.rs b/crates/socket-patch-core/src/patch/redirect/mod.rs index 9c148ad40..59d148cdf 100644 --- a/crates/socket-patch-core/src/patch/redirect/mod.rs +++ b/crates/socket-patch-core/src/patch/redirect/mod.rs @@ -5868,7 +5868,7 @@ fn go_token_safe(s: &str) -> bool { !s.is_empty() && !s.chars().any(|c| c.is_whitespace() || c.is_control()) } -// The committable shape (validated empirically — `docs/design/golang-hosted.md`): +// The committable shape (validated empirically — `docs/ecosystems.md#go-directory-replaces-and-gosum`): // // go.mod: replace => patch.socket.dev/gopatch/ // go.sum: patch.socket.dev/gopatch/ h1:… (zip dirhash) diff --git a/crates/socket-patch-core/src/policy/mod.rs b/crates/socket-patch-core/src/policy/mod.rs index 0577c45d0..15778f264 100644 --- a/crates/socket-patch-core/src/policy/mod.rs +++ b/crates/socket-patch-core/src/policy/mod.rs @@ -1,6 +1,6 @@ //! The repository's patch policy: the `patches` block and //! `projectIgnorePaths` of the root `socket.yml`, plus the built-in default -//! path ignores. See `docs/design/staged-rollout.md` §3-§4. +//! path ignores. See `docs/configuration.md#repository-patch-policy`. //! //! A policy only ever **narrows** what `scan` patches (trust boundary, //! CLI_CONTRACT.md): nothing here names an endpoint, a credential, a mode diff --git a/crates/socket-patch-core/src/rollout/stage.rs b/crates/socket-patch-core/src/rollout/stage.rs index eb6c08df3..9ebd7e7ac 100644 --- a/crates/socket-patch-core/src/rollout/stage.rs +++ b/crates/socket-patch-core/src/rollout/stage.rs @@ -1,4 +1,4 @@ -//! The per-run rollout stage (`docs/design/staged-rollout.md` §5, §9.2) +//! The per-run rollout stage (`docs/configuration.md#gradual-rollout`) //! the disk scan and the in-memory engine share: classify the selected //! offers against the recorded state, spend the budget on NEW packages //! most critical first once each mode's eligibility checks ran, and diff --git a/crates/socket-patch-core/src/vendor/go_sum_edit.rs b/crates/socket-patch-core/src/vendor/go_sum_edit.rs index e216b1475..a84c2d728 100644 --- a/crates/socket-patch-core/src/vendor/go_sum_edit.rs +++ b/crates/socket-patch-core/src/vendor/go_sum_edit.rs @@ -10,7 +10,7 @@ //! ``` //! //! Both lines are load-bearing on day-2 machines (validated empirically — -//! see `docs/design/golang-hosted.md`): under the default `-mod=readonly` a +//! see `docs/ecosystems.md#go-directory-replaces-and-gosum`): under the default `-mod=readonly` a //! missing zip line fails resolution up front, a missing `/go.mod` line fails //! after download, and a *present* line is verified against the fetched bytes //! (a wrong hash is a hard `SECURITY ERROR`). Crucially, go consults the diff --git a/crates/socket-patch-core/src/vendor/golang.rs b/crates/socket-patch-core/src/vendor/golang.rs index c54d16b87..83477a03c 100644 --- a/crates/socket-patch-core/src/vendor/golang.rs +++ b/crates/socket-patch-core/src/vendor/golang.rs @@ -1562,7 +1562,7 @@ mod tests { .any(|e| e.module == MODULE && e.owner == Some(ReplaceOwner::Vendor))); } - /// Cross-mode policy regression (docs/design/golang-hosted.md): vendor + /// Cross-mode policy regression (docs/ecosystems.md#go-directory-replaces-and-gosum): vendor /// takes over a hosted-mode replace through the LOCAL build leg too — only /// local *apply* refuses a Hosted-owned directive (its go-patches copy is /// uncommitted, so the takeover would break other machines). The hosted diff --git a/docs/configuration.md b/docs/configuration.md new file mode 100644 index 000000000..274692dcd --- /dev/null +++ b/docs/configuration.md @@ -0,0 +1,146 @@ +# Configuration + +Socket Patch reads command-line flags, environment variables, the Socket CLI's +persisted login, and repository patch-selection policy. For the complete flag and +environment-variable tables, see the +[CLI contract](../crates/socket-patch-cli/CLI_CONTRACT.md#environment-variables). + +## Authentication and endpoints + +Without a token, Socket Patch uses `https://patches-api.socket.dev` to access the +free patch catalog. With a token, it uses `https://api.socket.dev` and your +organization's patch entitlement. + +For the token, organization, and authenticated API URL, precedence is: + +1. Command-line flag. +2. Canonical environment variable, then its Socket CLI alias. +3. Socket CLI's persisted `config.json`. +4. Built-in default. + +| Setting | Flag | Environment variable | Socket CLI alias | Persisted key | +| --- | --- | --- | --- | --- | +| Token | `--api-token` | `SOCKET_API_TOKEN` | `SOCKET_CLI_API_TOKEN` | `apiToken` | +| Organization | `--org` | `SOCKET_ORG_SLUG` | `SOCKET_CLI_ORG_SLUG` | `defaultOrg` (also accepts `org`) | +| Authenticated API | `--api-url` | `SOCKET_API_URL` | `SOCKET_CLI_API_BASE_URL` | `apiBaseUrl` | + +The separate Socket CLI writes that file through `socket login` or `socket config`. +Socket Patch only reads it. Missing configuration is silent; an unreadable or +invalid login file produces a warning and falls back to the other sources. +Empty environment values are treated as unset. + +- `SOCKET_NO_CONFIG=1` disables persisted configuration. +- `SOCKET_NO_API_TOKEN=1` ignores ambient tokens from the environment and login + file; an explicit `--api-token` still wins. `SOCKET_CLI_NO_API_TOKEN` is an alias. +- `--proxy-url` / `SOCKET_PROXY_URL` selects the public patch API endpoint. It is + distinct from an HTTP forward proxy: use `HTTP_PROXY`, `HTTPS_PROXY`, and + `NO_PROXY` for those. +- `--offline` prohibits network access. `scan` and `get` require the patch API + and refuse offline operation. Other commands can use locally available state; + missing records or artifacts can still prevent completion. +- `SOCKET_NO_UPDATE_CHECK=1` disables the passive update notice. + +For other settings, precedence is flag → environment → default, except for the +repository policy scalars below. Socket Patch does not automatically load `.env` +files, and repository files cannot set credentials, API endpoints, or safety options. + +## Repository patch policy + +Commit a root `socket.yml` to control what `scan` may patch: + +```yaml +version: 2 +patches: + enabled: true + ecosystems: [npm, pypi] + minSeverity: high + maxNewPatches: 5 + includePaths: ["apps/**", "services/**"] + ignorePaths: ["services/legacy/**"] + ignorePackages: ["pkg:npm/example-package"] +``` + +Omit lists you do not need. The policy narrows selection; it does not choose a patch +mode or add dependencies. Socket Patch reads only `projectIgnorePaths` and the +`patches` block from the shared Socket configuration, plus the `version` needed to +validate that block. + +| Key under `patches` | Meaning | +| --- | --- | +| `enabled` | `false` reports candidates without changing patches or running prune | +| `ecosystems` | Limit selection to ecosystem slugs from the [support matrix](ecosystems.md) | +| `includePaths` / `ignorePaths` | Include or exclude project roots by their dependency-file paths | +| `packages` / `ignorePackages` | Include or exclude package names or PURLs, optionally with exact versions | +| `minSeverity` | Minimum severity: `critical`, `high`, `medium` (`moderate`), or `low`; omit for no floor | +| `maxNewPatches` | Maximum newly patched package identities per invocation; integer from 0 to 4294967295; omit for unlimited | + +A package already patched but now excluded is retained unchanged. Narrowing policy +never unpatches it. Use `rollback` or `remove` to remove a patch. + +### Precedence and scope + +CLI list filters (`--ecosystems`, `--package`, and PATHs) intersect with the file's +lists. Scalar settings follow flag → environment → file → default: + +```sh +socket-patch scan --min-severity critical +socket-patch scan --max-new-patches 2 +socket-patch scan --no-socket-yml +``` + +The scalar environment variables are `SOCKET_MIN_SEVERITY` and +`SOCKET_MAX_NEW_PATCHES`. `--no-socket-yml` / `SOCKET_NO_SOCKET_YML` bypasses the file; +built-in discovery exclusions still apply. + +Policy applies to every `scan` mode, including previews, and to the in-memory hosted +engine. `get` is an explicit selection: it bypasses policy and warns when a valid +policy would exclude its target. `apply`, `list`, `vex`, `vendor`, `repair`, `rollback`, +and `remove` do not apply selection policy to existing patches. + +Only the repository root's `socket.yml` or `socket.yaml` is read, not a file per +subdirectory. Repository lookup starts at `--cwd` and uses the nearest trusted `.git` +ancestor; without one it uses `--cwd`. Global scans read no repository policy. +If both filenames exist, their policies must agree. Invalid patch policy fails the +scan before network requests or writes rather than silently broadening selection. +See the [exact lookup and validation rules](../crates/socket-patch-cli/CLI_CONTRACT.md#socketyml-patch-policy-v50). + +### Paths and monorepos + +Path lists use case-insensitive gitignore semantics, relative to the repository +root. Later matches win; `!` negates, but cannot re-include a child of an ignored +directory. A root is excluded only when all of its dependency markers are ignored; +`includePaths` admits it when any marker matches. A workspace member sharing the +root's lockfile is part of that project: use package filters to restrict its patches. + +Discovered project roots under `test/`, `tests/`, `fixtures/`, `__fixtures__/`, and +`testdata/` are excluded by default. An explicitly named root (`--cwd` or a literal +PATH) skips these defaults, but still follows repository policy. A file pattern can +re-include a default, for example `ignorePaths: ["!/e2e/tests/"]`. + +```sh +socket-patch scan --cwd apps/web +socket-patch scan 'apps/*' --mode hosted +``` + +Each PATH in hosted or vendored mode is a project directory. Paths outside the +repository are rejected. For JSON output, scan one project per invocation. + +### Gradual rollout + +```sh +socket-patch scan --max-new-patches 5 # add at most five newly patched packages +socket-patch scan --max-new-patches 0 # upgrade existing patches only +socket-patch scan --max-new-patches none # remove the cap for this run +``` + +New patches are prioritized by severity, then advisory count, with deterministic +tie-breaking. Updates of already patched packages do not consume the cap. Multiple +project directories in one invocation share the budget and are visited in sorted +order; the same admitted package identity does not spend it twice. Separate commands +have separate budgets. + +A preview reports what would be admitted or deferred. JSON results include `policy` +and `rollout` summaries. Repeated scans advance against the state from previous runs; +in a PR workflow, merge the changed dependency files before expecting a fresh +checkout to advance to the next batch. The CLI does not schedule runs or count open +PRs. diff --git a/docs/design/configuration.md b/docs/design/configuration.md deleted file mode 100644 index 555b1db4f..000000000 --- a/docs/design/configuration.md +++ /dev/null @@ -1,178 +0,0 @@ -# Configuration design: env vars, the socket-cli config file, and what we deliberately don't read - -Status: **implemented** (v3.5); section 4 (`socket.yml` patch policy) is -**implemented** in v5.0 for its filters (`socket_patch_core::policy`; the -per-run cap follows with `--max-new-patches`, see `staged-rollout.md`). This document records the -settled design so future configuration surface grows inside it instead of -inventing new mechanisms. - -## Problem - -socket-patch's configuration was flags + `SOCKET_*` env vars only. That -architecture is correct for a CLI in the package-manager class, but it had -no story for "configure once, use everywhere": a user who ran -`socket login` with the JS Socket CLI still had to export -`SOCKET_API_TOKEN` for socket-patch. Meanwhile `.env`-style repo-local -config kept coming up as a "simpler setup" suggestion. - -## Decisions - -### 1. Flag > env > socket-cli config > default — per key - -Every flag keeps its clap `env =` binding (`SOCKET_*` prefix, CLI arg wins). -For exactly three settings the JS socket-cli's persisted login state is a -fallback layer between env and default: - -``` -apiToken / org / apiBaseUrl: - 1. CLI flag --api-token / --org / --api-url - 2. Canonical env SOCKET_API_TOKEN / SOCKET_ORG_SLUG / SOCKET_API_URL - 3. Peer alias env SOCKET_CLI_API_TOKEN / SOCKET_CLI_ORG_SLUG / SOCKET_CLI_API_BASE_URL - (silent in-process promotion before clap; canonical wins) - 4. socket-cli config /socket/settings/config.json (READ-ONLY) - keys: apiToken, defaultOrg (accepts alias "org"), apiBaseUrl - 5. Built-in default no token → public proxy; org → auto-resolve; - url → https://api.socket.dev - -Vetoes: - SOCKET_NO_API_TOKEN (alias SOCKET_CLI_NO_API_TOKEN) — ambient tokens - (layers 2–4) yield none; an explicit --api-token flag still wins. - SOCKET_NO_CONFIG — layer 4 disabled entirely (also the test-hermeticity - switch; the workspace .cargo/config.toml exports it for all cargo runs). - -Empty string == unset at every layer (repo-wide rule). -``` - -Implementation: `socket_patch_core::utils::socket_cli_config` (path -resolution mirrors socket-cli's `getSocketAppDataPath` — plus, on macOS, a -second probe of the legacy `~/.local/share` location that older socket-cli -releases wrote on every platform; lenient base64→JSON→plain-JSON decode, -allowlist copy, `OnceLock` disk cache with the gate checked per call), -consumed by `get_api_client_with_overrides` -(`api/client.rs`) and — for `apiBaseUrl` — by the shared -`resolve_api_base_url()` that the telemetry endpoint resolver also uses, so -client and telemetry can never disagree about the API host. The -`--api-url`/`--proxy-url` clap defaults were removed (fields are -`Option`) so the layer isn't dead code; the documented defaults are -applied at client construction. - -### 2. The file is socket-cli's; we only read it - -No `socket-patch login`, no `socket-patch config set`, no writes ever. The -file (base64-encoded JSON) is written by `socket login` / `socket config -set`. Corrupt or unreadable → one-shot stderr warning naming the path, then -treated as absent; missing → silent. `--json` stdout purity holds because -all diagnostics are stderr-only. Keys other than the three above -(`apiProxy`, `enforcedOrgs`, `skipAskToPersistDefaultOrg`) are socket-cli -UX policy and are ignored. - -### 3. Alignment across Socket tools - -- The python `socketsecurity` CLI already accepts `SOCKET_API_TOKEN`, so - the canonical names are the cross-tool bridge; no `SOCKET_SECURITY_*` - aliases were added. -- `socket.yml` is shared with the scanning product (projectIgnorePaths / - triggerPaths / issueRules / githubApp). As of v5.0 socket-patch reads - exactly two of its keys, `projectIgnorePaths` and a new `patches` block, - and nothing else (section 4). -- `SOCKET_PROXY_URL` (the public patch **endpoint**) must never be - conflated with socket-cli's `apiProxy` (an HTTP **forward proxy**). - Forward-proxy behavior comes from the standard - `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY` vars, which reqwest honors. - -### 4. `socket.yml` carries patch selection policy, never settings (v5.0) - -Revisits the v3.5 position that socket-patch does not read `socket.yml`. -Staged rollout needs a repo-owned, reviewable place to say which projects, -ecosystems and packages may be patched, a severity floor and a per-run cap -on new patches (`staged-rollout.md`). `socket.yml` is where Socket users -already express repo policy, it lives at the repo root, and a new -top-level `patches:` key is stripped or ignored by every existing parser. - -The trust boundary is unchanged and gains its positive half: - -- A repository file may **narrow or pace** what `scan` patches. It may - never widen it, name an endpoint or credential, choose a mode or download - format, or disable a safety interlock. The parser has no fields for any - of those; such keys are unknown keys and fail validation. -- Because the file only narrows, an unreadable file or an invalid - `patches` block fails closed (exit 1, `socket_yml_invalid`, nothing - written) instead of being treated as absent. (A repo with no `patches` - block and a malformed `projectIgnorePaths` gets a warning, so repos that - never opted in do not start failing.) This is the opposite of the socket-cli `config.json` rule above - (corrupt → warn and ignore), and deliberately so: ignoring a broken - user-level login file loses a convenience; ignoring a broken repo policy - widens the rollout. -- Lookup is bounded to the repository (nearest `.git` ancestor of - `--cwd` owned by the user, honoring `GIT_CEILING_DIRECTORIES`, else - `--cwd`), root files only, regular files only. -- Flags and env vars still win over the file for scalars (CLI > env > - file > default) and intersect with it for list filters; - `--no-socket-yml` / `SOCKET_NO_SOCKET_YML` ignores the file. -- Only `scan` (every mode) and the in-memory engine honor it. Commands - that report, attest or undo existing state (`list`, `vex`, `rollback`, - `remove`, `repair`, `apply`, `vendor`) ignore it; `get` bypasses it with - a warning. - -Implementation: `socket_patch_core::policy` (`SelectionPolicy::load` over a -`PolicyFs`: `DiskPolicyFs` for a checkout, `MemoryPolicyFs` for the -in-memory engine) parses the file as a YAML 1.2 event stream (serde-saphyr's -parser, so aliases are never expanded) and validates only `version`, -`projectIgnorePaths` and `patches`. Disk scan glue lives in -`commands/scan/policy.rs`; the flags in `commands/scan/socket_yml_args.rs`. -The full contract is CLI_CONTRACT.md "socket.yml patch policy". - -## Explicitly rejected - -| Idea | Why not | -|---|---| -| Auto-loading `.env` / `.env.local` | Trust boundary: the tool mutates installed packages while holding an API token; a file in a *cloned repo* must never redirect endpoints, disable interlocks, or spend the token. Also the wrong convention class — npm/cargo/pip/git read no `.env`; dotenv is an app-runtime convention. Users who want it have direnv/mise/dotenvx. | -| A new socket-patch config file (`.socket/config.toml`, …) | Duplicates socket-cli's persisted config; one more file format to trust, document, and migrate. | -| Writing to socket-cli's `config.json` | No login flow here; shared mutable state and format drift for zero benefit. | -| Honoring endpoints/credentials/interlock switches from repo-level files (manifest, socket.yml) | Same trust boundary as `.env`. Stated as a contract property in `CLI_CONTRACT.md`. Selection policy that only narrows is the one exception (section 4). | -| A `version: 3` socket.yml for the `patches` block | socket-cli rejects any version but 2; older ajv parsers would treat 3 as 2 anyway. The block is additive under `version: 2`. | -| Per-directory `socket.yml` files | No existing consumer supports them; one root file with `includePaths` covers monorepos. | -| `SOCKET_CLI_CONFIG` (ephemeral full-JSON config override) | Imports socket-cli's whole config vocabulary as a permanent compat contract. | -| Mapping `apiProxy` → anything | Forward-proxy vs patch-endpoint semantic trap; `HTTP_PROXY` et al. already work. | -| `enforcedOrgs` / `skipAskToPersistDefaultOrg` | Interactive socket-cli UX policy with no socket-patch analog. | - -## Deferred (designated homes, no implementation yet) - -- **Project-level behavioral defaults** (`downloadMode`, `vendorSource`, - mode): not planned. The v3.5 idea of a manifest `setup.defaults` block is - obsolete in v5 (hosted and vendored projects have no manifest and `setup` - is removed). Selection policy (ecosystems, packages, paths, severity, - per-run cap) went to `socket.yml` `patches` instead (section 4). Anything - that is not pure narrowing stays out of repo files. -- **Env cleanup sweep**: core's direct env readers (`SOCKET_OFFLINE` in - `utils/env_compat.rs`, `SOCKET_TELEMETRY_DISABLED` in `telemetry.rs`) - still match only `1|true`, unlike `parse_bool_flag`'s vocabulary (the CLI - mirrors `--offline` into `SOCKET_OFFLINE=1`, so only a hand-set env value - sees the narrower dialect); consider `FORCE_COLOR` as an alias for `CLICOLOR_FORCE` in - `ui::color_enabled` (which already honors `NO_COLOR`, `CLICOLOR`, - `CLICOLOR_FORCE` and `TERM=dumb`); document - `HTTP_PROXY`/`HTTPS_PROXY`/`NO_PROXY` support in the README. -- **`SOCKET_API_TOKEN_FILE` / keychain sourcing** for the token — the - conventional next step for secret hygiene; not urgent now that the - config-file path exists. - -## Test strategy (how this stays true) - -- socket.yml policy: table-driven unit tests in - `socket-patch-core/src/policy/` (every validation row, the lookup and - file-access rules, and a golden fixture generated from the npm `ignore` - package by `scripts/gen-ignore-golden.mjs`), the parser contract in - `tests/cli_parse_scan.rs`, disk e2e in `tests/e2e_socket_yml_policy.rs` - and disk/memory parity in `tests/hosted_memory_parity.rs`. - -- `tests/cli_config_fallback.rs` spawns the binary against fixture - `config.json` files (fresh process per case — the disk read is cached per - process) and pins: config token/apiBaseUrl authenticate, `defaultOrg` - skips org auto-resolve with telemetry following the config host+token, - env-beats-config per key, alias honored with canonical winning, corrupt - config warns while `--json` stdout parses, both toggles, and the - missing-file silence. -- Hermeticity: `.cargo/config.toml` `[env]` exports `SOCKET_NO_CONFIG=1` so - a developer's real login can never authenticate a test; the e2e env - scrub loops deliberately skip that variable so the guard survives into - spawned binaries. diff --git a/docs/design/golang-hosted-no-go.md b/docs/design/golang-hosted-no-go.md deleted file mode 100644 index 154f6d017..000000000 --- a/docs/design/golang-hosted-no-go.md +++ /dev/null @@ -1,115 +0,0 @@ -# Hosted redirect for Go: a deliberate no-go - -> **SUPERSEDED for the FREE tier (2026-08-13)** by -> [golang-hosted.md](golang-hosted.md): a fork-style `replace` onto a -> grant-free, content-addressed `patch.socket.dev/gopatch/` module plus -> committed `go.sum` lines dissolves all three blockers below — empirically, -> go consults the checksum database only for modules *absent* from `go.sum`, -> so committed hashes ARE the committable per-module exemption Blocker 1 said -> Go lacked, and a token-free module path defuses Blockers 2 and 3. **The -> analysis below still governs the PAID tier** (tokened URLs re-trigger -> Blockers 2 and 3), whose remedy remains vendored mode or the -> [ephemeral-CI recipe](#sanctioned-exception-ephemeral-ci-goproxy). - -**Status:** paid tier only — free-tier golang HOSTED mode is designed in -[golang-hosted.md](golang-hosted.md). -**Remedy:** `socket-patch vendor` (VENDORED mode: bytes committed to -`.socket/vendor/`, offline-verified, `replace => ./path` in `go.mod`). -**Warning code:** `redirect_golang_unsupported` (emitted for golang references -that carry no `goproxy` override — paid grants, or free patches the server has -not yet published a hosted Go module for — by both the Rust CLI rewriter and -the depscan backend's TS twin, -`workspaces/app/src/patches/registry-rewrite/golang.ts`). - -HOSTED mode's contract is a *committable, per-dependency* lockfile/registry -edit: only the patched dependency resolves from `patch.socket.dev`, everything -else resolves exactly where it did before, and install-time integrity -verification stays intact. Go cannot meet that contract. The patch-server does -serve a correct GOPROXY for the patched module -(`/patch-registry/golang/...`) — the problem is not serving the bytes, it is -that every way of *pointing* a Go build at them requires machine-local -configuration or breaks Go's verification model. Three independent blockers, -any one of which is disqualifying: - -## Blocker 1 — day-2 sumdb hard-fail, and the fix is uncommittable - -A patched module version (e.g. `v1.2.3-socketpatch.1`) does not exist in -`sum.golang.org`. With the default `GOSUMDB=sum.golang.org`, any `go` command -that resolves the patched version hard-fails checksum verification — not on -the machine that ran the redirect (its `go.sum` could carry the patched -hashes), but on **every other machine, day 2**: CI, a teammate's fresh clone, -a Docker build. The only sanctioned escape is `GOPRIVATE`/`GONOSUMCHECK`-style -configuration — which lives in the developer's environment or `go env -w` -(machine-local), **not** in any committable project file. A redirect that -requires every future builder to mutate their machine before `go build` works -is not a redirect; it is an outage with extra steps. Committing -`GOFLAGS`/`GONOSUMDB` via `go.work` or a wrapper script was rejected as a -shim around the real boundary: Go simply has no committable per-module -sumdb exemption. - -## Blocker 2 — module-path identity forces per-grant artifacts - -In Go, the module path **is** the identity: the `module` directive inside the -served `.mod`/zip must byte-match the import path the consumer requests. Our -hosted patch URLs are per-grant (`/{token}/{uuid}/`), and grants are -per-organization. Serving `example.com/lib` from a grant-scoped GOPROXY path -still works only while the module path inside the zip stays -`example.com/lib` — but then the zip's `h1:` dirhash must ALSO match what the -consumer's `go.sum` pins, which means the artifact must be built once and -byte-frozen. The patch converter is deliberately **build-once**: one artifact -per patch, shared by every grant (content-addressed, cache-friendly, -attestable). A Go redirect that embedded grant/token material into the module -zip (vanity import paths, rewritten module directives) would need one artifact -*per grant*, which is incompatible with the build-once converter and would -multiply storage and attestation surface by the number of customers. Rejected. - -## Blocker 3 — default GOPROXY publishes licensed bytes and leaks tokened URLs - -`GOPROXY` defaults to `proxy.golang.org,direct`. The moment any machine -without our override fetches the patched pseudo-version by name, the request -goes to **Google's public mirror**, which will try to fetch and then *cache -publicly forever* whatever it can reach. Two failure shapes: - -- If the patched module were reachable without auth, the public mirror would - republish licensed patch bytes to the world — a direct license violation. -- Because it is NOT reachable without auth, the fetch fails — but the - tokened URL (`/{token}/{uuid}/...`) has now been shipped to a third party's - logs, burning a capability URL we treat as a bearer secret. - -Either way, the default-GOPROXY world is hostile to a hosted Go patch: we -cannot control which resolver a downstream machine asks first, and both -possible outcomes (public caching, token leakage) are unacceptable. - -## Sanctioned exception: ephemeral-CI GOPROXY - -The one place machine-local configuration is acceptable is a **single-use, -ephemeral CI job**, where "the machine" is created and destroyed around one -build and no day-2 clone exists. Teams that cannot vendor may opt in, -explicitly and per-job: - -```yaml -# CI job (ephemeral runner) — NOT for developer machines or committed config. -env: - # Patched module resolves from Socket first, everything else falls through. - GOPROXY: "https://patch.socket.dev/patch-registry/golang/${SOCKET_PATCH_TOKEN}/${PATCH_UUID},https://proxy.golang.org,direct" - # The patched pseudo-version is not in sum.golang.org — exempt ONLY the - # patched module from sumdb lookups; all other modules stay verified. - GOPRIVATE: "example.com/patched-module" -steps: - - run: go mod download example.com/patched-module - - run: go build ./... -``` - -The token enters through the CI secret store, never a committed file; the -runner is discarded so no drifted `go env` survives; and `GOPRIVATE` is scoped -to the single patched module so sumdb verification stays on for the rest of -the graph. This recipe is documentation-only — neither `scan --mode hosted` nor -the backend PR flow will ever write it into a repository. - -## Decision - -`scan --mode hosted` (and the backend hosted PR flow) emit -`redirect_golang_unsupported` naming the remedy — run `socket-patch vendor` -(committable, offline-verified) — and the golang dependency is otherwise left -untouched. Vendored mode already gives Go users everything hosted mode -promises elsewhere: per-dependency, committable, verifiable at install time. diff --git a/docs/design/golang-hosted.md b/docs/design/golang-hosted.md deleted file mode 100644 index ad8a55fad..000000000 --- a/docs/design/golang-hosted.md +++ /dev/null @@ -1,211 +0,0 @@ -# Hosted redirect for Go: the fork-replace design (free tier) - -**Status:** implemented CLI-side (rewriter, golden fixture, day-2 e2e); waiting -on server-side publication (see [Server requirements](#server-requirements-depscan)). -**Supersedes:** [golang-hosted-no-go.md](golang-hosted-no-go.md) for the FREE -tier. The paid-tier analysis there (blockers 2 and 3 against tokened URLs) -still stands; paid golang references must not carry a `goproxy` override. - -## The shape - -`scan --mode hosted` commits exactly two files' worth of edits — no artifact -bytes, no machine-local configuration: - -```text -# go.mod -replace github.com/foo/bar v1.4.2 => patch.socket.dev/gopatch/ v1.4.2-socketpatch.1 - -# go.sum -patch.socket.dev/gopatch/ v1.4.2-socketpatch.1 h1:… (module-zip dirhash) -patch.socket.dev/gopatch/ v1.4.2-socketpatch.1/go.mod h1:… (served .mod bytes) -``` - -The patched module is published — grant-free and content-addressed, one -build-once artifact per patch — at a Socket-owned module path under -`patch.socket.dev/gopatch/`, served over the standard GOPROXY protocol. The -`replace` is Go's native fork mechanism; the committed `go.sum` lines are the -integrity pin. The rewriter also prunes the replaced original's two `go.sum` -lines: with the pinned replace in force, go removes the original from the -module graph entirely, and writing the tidy-stable state up front keeps the -first day-2 `go mod tidy` a byte-level no-op. - -## Why this dissolves the no-go doc's blockers (free tier) - -Every claim below was validated empirically against go 1.26 before the feature -was built (file-`GOPROXY` fixtures, fresh per-"machine" caches; the capstone -lives in `crates/socket-patch-cli/tests/e2e_golang_hosted_build.rs`). - -**Blocker 1 — day-2 sumdb hard-fail.** The no-go analysis assumed every fresh -machine re-consults `sum.golang.org` for the patched version. In fact go -consults the checksum database **only for modules absent from `go.sum`**. -Proven with a tripwire: every day-2 command run with `GOSUMDB` set to a bogus -database name (which fails loudly the moment it is consulted) — `go build`, -`go run`, `go test`, `go vet`, `go mod download`, `go mod verify`, -`go mod tidy` all succeed on an empty cache with only the committed -`go.mod` + `go.sum`, and zero `/sumdb/` requests appear in proxy logs. The -control (deleting one go.sum line) fails with `invalid GOSUMDB`, proving the -tripwire works. Committed `go.sum` lines ARE the committable per-module sumdb -exemption the old doc said Go didn't have. - -**Blocker 2 — module-path identity forces per-grant artifacts.** Only true if -grant material rides in the module path. The socket module path is -content-addressed by patch uuid and carries no token: one frozen artifact per -patch, shared by every consumer — build-once compatible. The zip's entry -prefix must be the socket path (`gopatch/@/`, go rejects any -other prefix), but its **internal `go.mod` may keep declaring the ORIGINAL -module path** — go accepts a replacement declaring either side of the arrow — -and patched sources MUST keep their original import spellings (rewriting them -to the socket path fails with `used for two different module paths`). So the -artifact is the upstream module with patched files, rezipped under a new -prefix: a zero-source-rewrite converter. - -**Blocker 3 — default GOPROXY publishes licensed bytes / leaks tokens.** For -the free tier, both horns are blunt: free patches are already anonymously -fetchable (production mints free-tier grants with no auth today), so -`proxy.golang.org` caching the module is republication of something already -public — and there is no token to leak because the path is grant-free. Google's -mirror caching the bytes is a robustness *win*: after first fetch, day-2 -builds succeed even if `patch.socket.dev` is down. (Also measured: with the -pinned replace in force, go never fetches or verifies the ORIGINAL module at -all — the patched graph builds even if the upstream registry is down.) - -## Day-2 contract (all validated) - -- Fresh clone/CI with committed `go.mod` + `go.sum`, empty caches, default - `-mod=readonly`, no `GOPRIVATE`/`GONOSUMDB`/`GOFLAGS`: builds and links the - patched code. -- `go.sum` verification keeps its teeth: one flipped character in the - committed `h1:` fails the build with go's checksum `SECURITY ERROR` — a - wrong CLI-written hash can never be silently built. (This is also why the - rewriter fails closed unless BOTH hashes are present: a replace committed - without its go.sum lines bricks every downstream `-mod=readonly` build.) -- `go mod tidy` is a byte-level no-op on the rewriter's output. -- `go mod vendor` vendors the PATCHED bytes under the upstream import path - (`vendor/modules.txt` records the replace) and `-mod=vendor` builds stay - patched — the vendored escape hatch composes. -- Proxy fetch sequence for the pinned module is exactly `.zip`, `.mod`, - `.info` (`.info` is required even for a fully pinned build; `/@v/list` and - `/@latest` are never requested on the pinned path). -- Module zips' `h1:` dirhash is content-derived (entry names + contents; - compression, mtimes, ordering, modes are ignored) — but the `/go.mod h1:` - hashes the SERVED `.mod` bytes, and go does NOT cross-check them against the - zip's internal `go.mod`. Server contract: freeze the two together. - -## Known limitations (documented, not blockers) - -- **Upgrade drift** (shared with local/vendored modes): `replace` is keyed on - module+version. `go get -u` / a require bump silently strands the pin — the - build reverts to the vulnerable version with zero warning while the inert - replace line stays in `go.mod`, and the next tidy strips the patch's go.sum - lines. Reliable text-only drift signals for a future `--check`: replace LHS - version ≠ require version; socket replace present with no matching go.sum - line. The rewriter refuses up front when `require` already disagrees with - the patch version (`redirect_golang_version_mismatch`). -- **Corporate proxies**: a `GOPROXY` pinned to an internal mirror (Artifactory - etc.) that cannot reach `patch.socket.dev` will 404 the socket module unless - the mirror passes through. Comma-fallback semantics also mean a proxy that - answers 403/500 (rather than 404/410) blocks the fetch. -- **Pre-modules packages**: modules without a `go.mod` are rejected by the - build pipeline (`UNSUPPORTED_ARCHIVE_FORMAT`) — same limit as vendored mode. -- **v2+ originals**: the socket module is always published in the v0/v1 - version range (a v2+ RHS version would force a `/v2` path suffix); the RHS - version need not relate to the original's. Not yet exercised against a real - `/v2` module — verify when the first such patch ships. -- **Paid tier**: unchanged no-go. Tokened URLs re-trigger blockers 2 and 3; - the ephemeral-CI `GOPROXY` recipe in the old doc remains the documented - paid workaround. - -## CLI implementation - -- `patch/redirect/mod.rs rewrite_golang` — pure rewriter, activates per-dep on - `registry_override.kind == "goproxy"`; absent override falls back to the - historical `redirect_golang_unsupported` warning. Fails closed (warning, no - partial writes) on: missing `go.mod`, missing/malformed `goModulePath` / - `goModuleVersion`, module path outside `patch.socket.dev/gopatch/`, missing - either integrity hash, require-version mismatch, user-authored replace - conflict. Warning codes: `redirect_golang_no_go_mod`, - `redirect_golang_missing_module`, `redirect_golang_untrusted_module_path`, - `redirect_golang_missing_integrity`, `redirect_golang_version_mismatch`, - `redirect_golang_replace_conflict`. -- `vendor/go_mod_edit.rs` — `ReplaceOwner::Hosted` (ownership = RHS module - path under `HOSTED_GO_MODULE_PREFIX`; go.mod and go.sum carry no other - marker), module-target parse (`rhs_module`/`rhs_version`) and - `upsert_hosted_replace_entry`, with in-place cross-owner takeover between - local `.socket/go-patches/`, vendored, and hosted directives. -- `vendor/go_sum_edit.rs` — pure go.sum editing: sorted upsert of the socket - module's two lines, prune of the replaced original's lines (removed lines - ride in the ledger `original` for revert), prefix-keyed removal. -- `scan/hosted.rs` — `go.mod`/`go.sum` added to `REDIRECT_CANDIDATE_FILES`; - the redirected-confirmation matcher additionally accepts the socket module - path (a Go rewrite contains no artifact/index URL). -- Wire schema — `Integrity.goModH1` (new) alongside `dirhashH1`; - `RegistryOverrideIdentifiers.goModuleVersion` (new) alongside the - previously-reserved `goModulePath`. -- Cross-mode policy (adversarially reviewed): takeover into hosted (from a - local `.socket/go-patches/` or vendored replace) and vendor-takes-over-hosted - are supported, in-place, and ledger-recorded with the replaced directive in - `original`; **local apply refuses** a Hosted-owned replace (taking it over - would strand the pruned go.sum lines) and `apply --check` exempts - hosted-owned modules from MissingReplace drift. A committed pin whose - version `require` no longer selects is reconciled away (directive + go.sum - lines removed) rather than left to confirm a redirect it no longer performs. - `vendor --revert` after a hosted takeover warns to re-run - `scan --mode hosted` or `go mod tidy`. -- Tests — unit suite in `redirect/mod.rs`; golden fixture - `tests/fixtures/redirect/golang/gomod/basic/` (the cross-language contract - the depscan TS twin must match byte-identically); capstone - `e2e_golang_hosted_build.rs` (real go, file proxy, bogus-GOSUMDB tripwire, - tidy no-op, tamper SECURITY ERROR). - -## Server requirements (depscan) - -What already exists (verified in code + live prod probes, 2026-08-13): - -- The GOPROXY protocol implementation (`patch-serving/registry-decision.ts` - `golangDecision`: `/@v/list`, `.info`, `.mod`, `.zip`, `/@latest`) — deployed - and executing in prod, but token-gated - (`/patch-registry/golang/{token}/{uuid}/…`) and serving the ORIGINAL module - path + version. -- A byte-deterministic golang repack (STORE-only zips, epoch mtimes, sorted - names; e2e-pinned to reproduce `sum.golang.org`'s h1 for unpatched input). -- `hashGoZip` (persisted as `package_dirhash_h1`) and `hashGoMod` (exists in - `lib/src/go/sum.ts` but never persisted or exposed). -- Anonymous free-tier grant minting via `POST /patch/package`. - -What the free-tier Go redirect needs: - -1. **A second artifact flavor per golang patch**: same patched contents, - zip entries prefixed `patch.socket.dev/gopatch/@/` - (internal `go.mod` unchanged — keep declaring the original path). Because - h1 covers entry names, this flavor has its OWN dirhash: persist both its - zip h1 and its `/go.mod` h1 (`hashGoMod` of the served `.mod` bytes). -2. **A token-free route family** serving that flavor over the GOPROXY - protocol at a stable public path for module `patch.socket.dev/gopatch/`, - free-tier patches only. Strictly 404/410 anything else (including bare - parent-prefix `/@v/list` probes go issues during tidy) so comma-fallback - proxies fall through. `.info` needs no `Time` field. -3. **`?go-get=1` discovery**: serve - `` - at the module path on `patch.socket.dev`, so `GOPROXY=direct` users and - `proxy.golang.org` itself can resolve it (validated end-to-end with the - `mod` VCS type; `sum.golang.org`'s own lookup does the same discovery). -4. **Reference API**: populate `registryOverride.kind = "goproxy"`, - `indexUrl` = the proxy base (the server origin), and on `identifiers`: - `goModulePath` / `goModuleVersion` (`-socketpatch.`, always - v0/v1-range) plus the hash pair `goZipDirhashH1` (the gopatch-flavor - zip h1) and `goModH1`. The pair rides **identifiers**, not the tarball - artifact's integrity — the tarball `dirhashH1` must stay the - original-path flavor, which released CLIs verify vendor-mode downloads - against. DepOverride builders (this CLI's `scan/hosted.rs` and the - backend's hosted PR flow) merge the pair into the normalized - `integrity.dirhashH1`/`goModH1` that the rewriters read. FREE patches - only — never emit a `goproxy` override for a paid-tier grant. -5. **Write-once invariant (the kill-shot risk)**: once a - `gopatch/@` is fetchable, `proxy.golang.org` caches its - bytes immutably and consumers commit its hashes. Any rebuild that changes - bytes MUST bump `-socketpatch.`; the existing admin - "regenerate to populate" rebuild practice must be forbidden for published - gopatch versions. -6. **TS twin**: replace `registry-rewrite/golang.ts`'s unconditional warning - with the byte-identical twin of the Rust rewriter, pinned by the shared - `golang/gomod` golden fixture. diff --git a/docs/design/nuget-vendoring-research/adversarial-env.md b/docs/design/nuget-vendoring-research/adversarial-env.md deleted file mode 100644 index 20b9e347b..000000000 --- a/docs/design/nuget-vendoring-research/adversarial-env.md +++ /dev/null @@ -1,162 +0,0 @@ -# Adversarial review: NuGet vendoring v2 (unique-version fallback seed) on real environments and CI - -I found one blocker and seven majors. The blocker is that git line-ending normalization breaks the committed seed. On a fresh CI clone the build fails with SOCKETPATCH002, while it still passes on the author's machine. The design's core behaviour survived the attacks I ran: the redirects, SOCKETPATCH005, the Docker-style bypass and symlinked checkouts all behaved as designed. - -**How I tested.** SDK 8.0.131 with HOME, NUGET_PACKAGES, NUGET_HTTP_CACHE_PATH, TMPDIR and DOTNET_CLI_HOME isolated under `scratchpad/adv-env/`, one dotnet process at a time. I built a Lib/App sln fixture with locks. `adv-env/r1/.socket/vendor/nuget/socket-patch.targets` is the §6.3 targets file rendered almost exactly (seed-presence check, direct redirect and the full guard). I added only two `Message` lines for diagnostics. The seed is the design-D 13.0.1 seed under a uuid root. Clones of the fixture are in `adv-env/c1`, `c2` and `c3`. Git experiments are in `adv-env/git1`. - -Labels: **VERIFIED** means I ran it here. **REASONED** means I did not run it. - ---- - -## BLOCKER - -### B1. Git EOL normalization changes seed bytes, so every fresh clone fails SOCKETPATCH002 (VERIFIED) -- **Scenario.** - - The repo has `* text=auto` in `.gitattributes`. That is the Visual Studio template default and is common in .NET repos. - - Newtonsoft's nuspec, `LICENSE.md` and `lib/*/Newtonsoft.Json.xml` are CRLF. I checked: 38/38, 20/20 and 11305/11305 lines are CRLF. - - Git stores them as LF in the index. The author's working tree stays CRLF and `git status` is clean, so every local build passes. -- **Wrong outcome.** - - On a fresh CI clone the files check out as LF. The inventory check then fails: - - `error SOCKETPATCH002: seed modified: …/13.0.1.1843260417/LICENSE.md` - - VERIFIED in `adv-env/c1`, built after `git clone`. - - The same class of failure also occurs with: - - `core.autocrlf=true` (the Git for Windows installer default): LF text files become CRLF on checkout. VERIFIED: a committed LF `x.json` came back `\r\n` in the autocrlf clone. - - `core.autocrlf=input` on the author's machine. - - `*.xml text eol=crlf` rules. - - A root LFS rule such as `*.dll filter=lfs`. With `actions/checkout`'s default `lfs: false`, CI gets pointer files and fails SOCKETPATCH002. That failure is loud, but it is a surprise. -- **Fix.** - - The CLI writes `.socket/vendor/nuget/.gitattributes` **before** the user's first `git add`: - ``` - /*-*-*-*-*/** -text -filter -diff -merge - socket-patch.targets text eol=lf - .gitignore text eol=lf - ``` - - VERIFIED: `git check-attr` shows text, filter and eol all unset under a hostile root file (`* text=auto`, `*.dll filter=lfs`, `*.xml text eol=crlf`). An autocrlf=true clone then passes the hash check, and `dotnet build` succeeds (`adv-env/c2`). - - Blobs committed before the attribute existed stay normalized. I had to `git rm --cached` and re-add them. - - So `vendor --check` must compare the inventory against the committed blobs (`git cat-file` of `HEAD:`), not the working tree. It should also check `git ls-files --eol` and refuse or fix with `vendor_nuget_eol_normalized`. Otherwise the author's green local run hides the CI failure. - - Add a golden-image e2e leg: commit, then `git clone`, then build. Run it with both `text=auto` and `autocrlf=true`. - ---- - -## MAJOR - -### M1. The same V′ in the GPF (same bytes) fails SOCKETPATCH003 and prints destructive advice (VERIFIED) -- **Scenario.** A shared machine or self-hosted runner with a shared `~/.nuget/packages`, where one repo uses the feed tier (§10) or, later, hosted V′ (§11.2) for the same patch. Those tiers extract `//` into the GPF, and the GPF beats fallback folders at asset resolution. -- **Wrong outcome.** - - The fallback-tier repo resolves the GPF copy and fails: - - `error SOCKETPATCH003: foreign …/gpf/newtonsoft.json/13.0.1.1843260417/lib/netstandard2.0/Newtonsoft.Json.dll` - - This happens even with byte-identical files. VERIFIED in `adv-env/c2`: I copied the seed into the GPF, `restore --locked-mode` succeeded, and the build failed. - - The error text says "Delete that package folder". Doing that breaks the other repo, which re-extracts the package, and the two repos keep undoing each other. - - This contradicts the design's own rule that one V′ is always one byte sequence (§6.1). -- **Fix.** - - Key `SocketPatchNuGetHashes` by `//`, not by `/…`. Hash the consumed files wherever they resolved. - - Accept files from a foreign root when all of them match the inventory. Fail SOCKETPATCH003 only when they differ. This is also the feed-tier guard, so the two tiers share one code path. - - Alternatively, add a tier bit to V′ so fallback V′ never appears in any feed. That costs a bit of the 29-bit uuid space. - -### M2. The guard runs in design-time builds, contrary to §9 and G9 (VERIFIED) -- **Scenario.** VS, Rider or C# Dev Kit run a design-time build (`ResolveAssemblyReferencesDesignTime`, `DesignTimeBuild=true`). -- **Wrong outcome.** - - `ResolvePackageAssets` runs, so the `AfterTargets` guard runs too. VERIFIED: `SPGUARD-RAN DesignTimeBuild='true'`. - - Any SOCKETPATCH001/002/003/005 condition, such as a stale restore right after `git pull`, fails the design-time build. IntelliSense then shows "project load" errors and references go unresolved on every edit. - - §9 states "The guard runs only in real builds", which is incorrect. -- **Fix.** Add `and '$(DesignTimeBuild)' != 'true'` to the guard condition. Optionally, emit SOCKETPATCH005/003 as warnings when `$(BuildingInsideVisualStudio)` is true and keep the errors for the command line. Fix the §9 text. - -### M3. Windows paths are about 80 characters deeper than the GPF (REASONED, lengths computed) -- **Scenario.** The seed sits at `.socket\vendor\nuget\<36-char uuid>\\\…`. - - Under the GitHub Actions workspace, `D:\a\my-service-repo\my-service-repo\` plus the Microsoft.Extensions.DependencyInjection.Abstractions `lib/netstandard2.1/*.xml` gives **242** characters. - - The repo-relative part is only 205, so the §9 warning ("seed path > 240") never fires. - - `runtimes//native/…` and satellite paths are deeper still. -- **Wrong outcome.** - - Git for Windows (`core.longpaths` is false by default) fails checkout with "Filename too long". - - MSBuild.exe on .NET Framework and some tools hit MAX_PATH. The same package works fine from `%USERPROFILE%\.nuget\packages`. -- **Fix.** - - Use a uuid8 directory name (with collision refusal). - - Compute the warning on an **absolute** path under a pessimistic prefix: 60 characters for CI, or the real root. - - Refuse above 250 unless `--allow-long-paths`. - - Document `git config core.longpaths true`. - - Add the Windows leg to the prototype acceptance criteria, not only to promotion. - -### M4. EOL-sensitive byte comparisons in the hot path, `--check` and revert break on Windows and on mixed teams (REASONED; the conversion is VERIFIED in B1) -- **Scenario.** `fallback_in_sync` and `--check` require the targets file and `.gitignore` to be byte-equal to a fresh render. Lock and import records compare the live text with the recorded `new` or `original`. - - With autocrlf=true, a Windows checkout turns LF-committed files into CRLF (VERIFIED for `.json`). -- **Wrong outcome.** - - `vendor --check` fails on every Windows CI job. - - The hot path re-renders on every run. - - Lock and import revert on Windows treats every record as drift. It keeps the seed, and the revert is not clean. -- **Fix.** - - Pin `eol=lf` on the generated files via B1's `.gitattributes`. - - For user-tree files (locks, `Directory.Build.targets`), compare after normalizing CRLF to LF. Splice using the live file's detected EOL. - - Store records as EOL-neutral text plus the observed EOL. - -### M5. Mixed packages.config and SDK repos are left undefined (REASONED) -- **Scenario.** An enterprise solution has old packages.config web apps and new SDK libraries that use the same id@V. This is very common. -- **Wrong outcome.** - - §5 and §7.1 route packages.config to legacy and allow one tier per repo. `vendor_nuget_layout_mixed` refuses a same-id legacy entry. - - So either the whole patch is refused, or the legacy path runs. The legacy path brings back the nuget.config catch-all mapping and same-version GPF poisoning for the whole machine, which is exactly what v2 set out to remove. - - The design never says which of the two happens. -- **Fix.** - - Define a single entry with two wiring sets: the legacy feed for packages.config projects only, and the fallback tier for SDK projects. - - Alternatively, refuse explicitly with `vendor_nuget_mixed_project_styles` and describe the options. - - Either way, add a docker leg that uses nuget.exe under mono (for example the `mono` image), since no packages.config coverage exists today. - -### M6. `vendor --check` and the hot path depend on restore outputs (REASONED) -- **Scenario.** A typical CI job runs `git clean -fdx` (or starts from a fresh checkout), then `socket-patch vendor --check`, then `dotnet restore`. -- **Wrong outcome.** - - Lockless projects have no `obj/project.assets.json`. - - `plan_closure` then refuses with `vendor_nuget_unrestored`, or reports `closure_changed`, so the pre-restore check fails for no real reason. -- **Fix.** - - Persist the closure in state and make `--check` validate against it. - - Recompute the closure only when assets are present. - - Add a fallback that plans from `dotnet msbuild -getItem:PackageReference` without a restore. - -### M7. Renovate and Dependabot rewrite or misread the generated targets file (REASONED) -- **Renovate.** Renovate's nuget manager matches `\.(props|targets)$` and parses `PackageReference Update=… Version=`. It can propose `[13.0.1.N]` → `[13.0.3]` in `socket-patch.targets`. - - Renovate's default `ignorePaths` (`**/vendor/**`, dot-matching) probably covers `.socket/vendor/nuget/`. - - But any repo that sets `ignorePaths` replaces that default and is then exposed. -- **Dependabot.** Dependabot's native (MSBuild-evaluating) updater sees the evaluated version V′ and may try to edit the file where it is declared, or skip the dependency. -- **Wrong outcome.** - - The redirect silently pins some other version. - - `SocketPatchNuGetUpstream` only knows 13.0.1, so SOCKETPATCH005 does not fire. - - The patch drops out, and only the lock diff and a later `--check` show it. -- **Fix.** - - Put the versions in properties (`Version="$(_SpV_3f9a01bc)"`) so regex tools see no literal. - - Add a render-hash self-check: a `SocketPatchTargetsHash` property that the CLI verifies, plus a SOCKETPATCH006 build warning when the file was edited. - - Have `vendor` print or emit `ignorePaths: [".socket/**"]` for Renovate. - - Add a Q3 experiment with the Dependabot nuget updater container. - ---- - -## MINOR - -| # | Scenario | Outcome | Fix | -|---|---|---|---| -| m1 | Sparse checkout in cone mode on monorepos: root files are included, root directories are not. | `.socket/` is absent and every build fails MSB4019. VERIFIED (`adv-env/c3`). Loud, but a friction failure mode for every sparse user. | Emit a comment above the Import that names `git sparse-checkout add .socket/vendor/nuget`. `vendor` prints it. Document it for Scalar users. | -| m2 | Declared literal `[13.0.1]` or `13.0.1.0` in a new project. | The redirect does not engage and SOCKETPATCH005 fires. VERIFIED for both. The failure is loud, but CLI planning treats it as "literal known". | Emit one redirect condition per observed normalized-equal literal (`13.0.1`, `13.0.1.0`, `[13.0.1]`, `[13.0.1, )`). | -| m3 | Docker `COPY *.csproj` → `restore` without DBT or `.socket` → `COPY . .` → `build --no-restore`. | SOCKETPATCH005, so fail-closed as designed. VERIFIED. Every Dockerfile needs `COPY Directory.Build.targets .socket/vendor/nuget`, and the layer cache is invalidated per patch. | Document it. `vendor` scans for `Dockerfile*` with `dotnet restore` and warns `vendor_nuget_dockerfile_copy`. | -| m4 | `git clean -fdx` after `vendor` but before commit. | The untracked seed and targets are deleted. The tracked DBT edit stays, giving MSB4019. | Print "commit `.socket/vendor/nuget`" in the outcome. `--check` detects untracked seeds. | -| m5 | Seeds for big packages (native runtimes, analyzers, satellites). | GitHub hard-limits files to 100 MB and warns at 50 MB. The whole package goes into history once per uuid, and org pre-receive hooks may demand LFS. | Cap file and seed size with `vendor_nuget_seed_too_large`. Record a per-repo LFS opt-in only with `checkout lfs:true` documented. Future G-experiment: prune the seed to the closure's TFMs and RIDs (contentHash comes only from `.nupkg.metadata`). | -| m6 | Seed entries that differ only by case, on macOS or Windows. | Checkout collision and SOCKETPATCH002. | Refuse at vendor time on a case-folded inventory collision. | -| m7 | Seed missing, VS restore (no SOCKETPATCH001 there), lockless, and a source that serves V′. V′ is predictable from the committed uuid. | An attacker's `build/*.targets` imports at evaluation, before any guard. This needs control of the id on a source (private or virtual feeds, unreserved ids). | The server-side collision check must cover the org's configured upstreams, not just nuget.org. Refuse the fallback tier for ids that are not prefix-reserved on multi-upstream feeds, or make redirects depend on `Exists(seed)` combined with a hard evaluation error. | -| m8 | GitHub dependency graph, Trivy and CycloneDX read `packages.lock.json`. | They see `12.0.1.N`, so alerts persist and Dependabot security PRs bump the version and drop the patch. Tools that fetch nuspec metadata from nuget.org for V′ fail. | depscan SBOM mapping (already a GA blocker). Document the alert behaviour. Consider emitting Dependabot `ignore` entries. | -| m9 | actions/setup-dotnet `cache: true` keys on the hash of the lock files. | One cache miss per vendor or revert. Also, `NUGET_PACKAGES=${{github.workspace}}/.nuget/packages` puts the GPF inside the repo, and `discover_projects` does not skip `.nuget/` (template packages contain `*.csproj`). | Skip every dot-directory and any directory that is a configured package folder during discovery. | -| m10 | Concurrent restores or builds. | No writes to seed roots, so this is safe (REASONED). The pack hook writes `obj/socket-patch-pack/`, per project. | None needed. Add one parallel `-m` sln leg to the docker suite. | - ---- - -## Attacks that failed (the design holds) -- **Symlinked checkout path.** The resolved paths and `SocketPatchNuGetDir` stay consistent, so the guard passes. VERIFIED. -- **Guard cost.** 52 ms per project for the full 8.7 MB Newtonsoft seed, with `GetFileHash` at 10 ms. Stamp-free hashing is affordable. VERIFIED. -- **Guard targets as written.** They parse and work on SDK 8: the unquoted `StartsWith($(...))`, the `Substring` key and the `%(SpKey)` batching. That is partial G1 evidence, one root only. VERIFIED. -- **Direct redirect, auto-follow and locked-mode restore from the fallback root with a warm upstream 13.0.1 in the GPF.** VERIFIED. -- **Accepted from earlier research, not re-run here:** `NUGET_PACKAGES`, `--packages`, `RestorePackagesPath`, `locals all --clear` and offline for the patched package (VERIFIED-D and VERIFIED-C). - -## Required design changes, in priority order -1. Write the nested `.gitattributes` from B1, and have `--check` compare against committed blobs. -2. Make the hash guard location-independent, as in M1. -3. Skip the guard in design-time builds. -4. Use a uuid8 directory and compute the MAX_PATH check on absolute paths. -5. Compare EOL-neutrally in the hot path, `--check` and revert. -6. Define the mixed packages.config policy. -7. Make `--check` work before any restore. -8. Stop exposing literal versions in the targets file, and add a render-hash check. -9. Add real-clone e2e legs (`text=auto`, `autocrlf=true`, sparse, Windows) to the **prototype** acceptance criteria. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/adversarial-integrity.md b/docs/design/nuget-vendoring-research/adversarial-integrity.md deleted file mode 100644 index 24678743a..000000000 --- a/docs/design/nuget-vendoring-research/adversarial-integrity.md +++ /dev/null @@ -1,192 +0,0 @@ -# Adversarial integrity review: NuGet vendoring v2 (unique-version fallback seed) - -**Verdict: not ready.** The design's integrity story has one gap that decides everything else. Nothing pins the set of files in the committed seed, and every check (lock `contentHash`, the `SOCKETPATCH002` tables, `.nupkg.metadata`, `state.json` `fileInventory`) points back at other files in the same repo. I proved these gaps with dotnet runs: -- a tampered seed, or one with files added, passes `--locked-mode`; -- files added to the seed run as MSBuild code before the guard runs, and can switch the guard off; -- an environment variable switches the guard off; -- a nested `Directory.Build.targets` added later silently builds upstream; -- git's `* text=auto` rewrites seed bytes, so `SOCKETPATCH002` fails on every clean clone. - -Most fixes are cheap. - -**Setup.** .NET SDK 8.0.131. HOME, NUGET_PACKAGES, NUGET_HTTP_CACHE_PATH, TMPDIR and DOTNET_CLI_HOME were isolated under `/adv-integrity/` (`env.sh`). The package feed was an offline local folder holding upstream Newtonsoft.Json 13.0.1. The seed was the design-D e1 seed `13.0.1.1843260417`, placed at `.socket/vendor/nuget/u1/`. The fixture repo is `adv-integrity/base`. It uses the design's §6.3 guard logic (redirect, `SOCKETPATCH005`/`003`/`002`, and the `SocketPatchSeedFile` hash check) almost unchanged. The other experiments ran in `x0` to `x5`. - -Labels: **VERIFIED** means I ran it here. **REASONED** means it follows from verified facts or from the code but I did not run it. **DOCS** means it comes from documentation only. - ---- - -## Blockers - -### B1. The seed's file set is not pinned. Added files are consumed, run before the guard, and can turn it off. The lock pins nothing. -- **Scenario.** A PR, a bad merge, or a compromised dependency bot changes a seed dll. It also adds `build/netstandard2.0/Newtonsoft.Json.props` and `.targets`, which are not in the nuspec, not in `fileInventory`, and not in `SocketPatchSeedFile`. -- **Result (VERIFIED, `x1`).** - - On a fresh clone, `dotnet restore --locked-mode` succeeds with the tampered dll. The lock `contentHash` is compared only with `.nupkg.metadata`, and that file sits in the seed and was not changed. - - NuGet enumerates the seed directory, so the added `build/` files go into `project.assets.json` and are imported: the props through `nuget.g.props`, the targets through `nuget.g.targets`. - - The props set `SocketPatchNuGetGuard=false`. `dotnet build` then prints `EVIL: injected seed build/ code executed` and `Build succeeded`. No `SOCKETPATCH002` is raised, even though the dll was changed. -- **What this means.** - - In the fallback tier the lock gives version identity only, not integrity. The claim in §2.5/§4 that the patched package is integrity-pinned is overstated. - - The design's inventory check hashes only the files it lists, never "these files and no others". It also runs only when `_SpLocal != ''`. - - A single added file in a large, binary-heavy seed diff is easy for a reviewer to miss. -- **Severity: blocker.** -- **Fixes (all needed):** - 1. **Set-equality check at restore time.** Add a target at `BeforeTargets="_GenerateRestoreGraph;CollectPackageReferences"` that globs `$(SocketPatchNuGetDir)/**` (including dotfiles) and fails if the glob differs from the inventory or any hash differs. Restore runs in its own evaluation before `nuget.g.*` is regenerated, so on a clean CI checkout the check runs before the planted code is imported. Run it unconditionally, not gated on `_SpLocal`. - 2. **The CLI checks set equality too.** `fallback_in_sync`, `verify.rs` and `vendor --check` should walk the directory, reject any extra file, symlink or non-regular file, and compare against `fileInventory`. - 3. **Anchor the seed outside the repo.** Add `vendor --check --online`, which rebuilds the expected tree from an independent source and diffs the committed seed against it byte for byte. The source is either the SRI-checked service `nupkg-socket-version`, or the upstream nupkg (with its signature or depscan `upstreamSha512` checked) plus the patch afterHashes. Recommend it as the CI gate. Without it, every pin is self-referential (see M6). - 4. **Harden the guard property.** Covered in M1. - -### B2. Git line-ending normalisation changes seed bytes, so SOCKETPATCH002 fails on clean clones. -- **Scenario.** The repo has `* text=auto` in `.gitattributes`, as the common VisualStudio template does, or a developer uses `core.autocrlf=true`, the Git for Windows default. -- **Result (VERIFIED, `x5`, `x4`).** - - With `* text=auto`, `git add` normalises CRLF to LF in `newtonsoft.json.nuspec`, `LICENSE.md` and `lib/*/Newtonsoft.Json.xml`. The clone's hashes differ from the originals (for example the nuspec goes from `a1d0fb81…` to `2fd73470…`). The dll is unchanged. - - With `autocrlf=true`, LF-only text members such as `socket-patched.txt` are rewritten on checkout. -- **Wrong outcome.** - - The developer who vendored still has the original bytes and passes. Every other clone and CI fails `SOCKETPATCH002` on the `SocketPatchSeedFile` rows. - - The hot path always sees drift, so `vendor` rewrites the seed every run. - - Legacy mode never hit this, because a `.nupkg` is binary to git. -- **Severity: blocker** (correctness and CI friction; it makes the integrity guard useless in practice). -- **Fix.** - - Generate `.socket/vendor/nuget/.gitattributes` containing `* -text -diff -merge -filter`. This also turns off LFS. - - After writing, run `git check-attr text eol filter -- `. Refuse with `vendor_artifact_git_transformed` if any file is still text or filtered. - - Add a case to the Docker test: a repo with `* text=auto`, then clone and build. - - If `*.dll filter=lfs` survives (the negation does not win), LFS pointer files in the checkout give a loud `SOCKETPATCH002` rather than a silent failure, but refuse at vendor time anyway. - ---- - -## Major - -### M1. The guard can be turned off by an environment variable, package props, or a Directory.Build.rsp. -- **VERIFIED (`x3`):** - - `SocketPatchNuGetGuard=false dotnet build` with a tampered seed dll ends in `Build succeeded`. MSBuild reads environment variables as properties. One stray variable in a CI template turns off every guard in the org. - - B1 showed that package-level props can do the same. -- **REASONED:** a committed `Directory.Build.rsp` containing `-p:SocketPatchNuGetGuard=false`, or `SocketPatchNuGetAllowUnpatched=true` in the environment, does the same thing and is easy to miss in review. -- **Fix (VERIFIED, `x1` second run).** - - Assign `true` unconditionally in `socket-patch.targets`. The `-pp` output shows `Directory.Build.targets` imported after the package `build/*.targets` (line 9218 vs 9173). A project or package cannot override that assignment, and neither can an environment variable. Only a global `-p:` can. With this change, the props attack was stopped and `SOCKETPATCH002` fired. - - Because our file is imported last, our `SocketPatchNuGetGuard` target definition also wins over a package that redefines the target (VERIFIED). A `BeforeTargets` hook in the planted code is still arbitrary code, which is why B1's restore-time check is the real defence. - - Replace the free `SocketPatchNuGetAllowUnpatched` property with a project allowlist generated by the CLI from `state.json`. - - Make `vendor --check` flag `Directory.Build.rsp` and `MSBuild.rsp` files that mention `SocketPatch*`. - -### M2. A nested Directory.Build.targets added later hides the import. The project builds upstream silently and SOCKETPATCH005 never runs. -- **VERIFIED (`x3`).** - - Adding `src/Directory.Build.targets`, which does not chain to the root, plus a new `src/New/New.csproj` that references 13.0.1, gives `Build succeeded`. - - A new lock is created with `resolved: 13.0.1` and the upstream hash. No `SOCKETPATCH*` error appears. -- **Why the design misses it.** §4 and §9 say `SOCKETPATCH005` covers new projects. It covers them only if the import is reached. `ImportDirectoryBuildTargets=false` added later behaves the same way. -- **Severity: major.** The build silently ships the known-vulnerable version. -- **Fix.** - - `vendor --check` (the CI gate) evaluates every discovered project with `dotnet msbuild -getProperty:SocketPatchNuGetTargetsImported` (batched, or with `-graph` from the sln). It fails if any project that resolves the patched id at V is missing the import. - - Also, when writing a nested DBT, prefer adding the `GetPathOfFileAbove` chain line. - - Document that the protection holds only up to the next nested DBT. - -### M3. A copy of V′ in the global packages folder takes priority over the committed seed. -The global packages folder (GPF) is NuGet's shared package cache. -- **VERIFIED (`x2`).** - - When `$NUGET_PACKAGES/newtonsoft.json/13.0.1.1843260417/` holds different dll bytes and a copy of the seed's `.nupkg.metadata`, `restore --locked-mode` succeeds and resolves from the GPF. - - The guard then fires `SOCKETPATCH003` correctly. - - If that GPF copy also carries a `build/*.props` that sets `SocketPatchNuGetGuard=false`, the build ends in `Build succeeded` with the other bytes in `bin/`. -- **Consequences.** - - (a) §9's "NU1403 when locked" holds only when the planted `.nupkg.metadata` hash differs. A copied directory, for example from a cache-sync tool, passes. With M1's fix, `SOCKETPATCH003` still catches it. - - (b) **Cross-tier false positive (REASONED from the verified priority).** Once any feed-tier repo, or the future hosted V′ (§11.2), puts builder-0 V′ into a shared CI or developer GPF, every fallback-tier repo using that uuid fails `SOCKETPATCH003` on that machine, although the bytes are identical. The GPF is never refreshed, so the failure persists until someone deletes the entry by hand. -- **Fix.** - - Make the resolved-root check depend on content. Accept a foreign root when the package's whole file set hashes equal the inventory (same set-equality as B1), and fail otherwise. - - Also narrow the `StartsWith` prefix from `SocketPatchNuGetDir` to the exact `` root. Today one uuid's V′ served from a different uuid directory passes (minor). - -### M4. Builder bit 1 does not map to a single byte sequence. In the feed tier this gives persistent NU1403 on a shared GPF. -- **REASONED.** Builder 1 covers three different byte producers: - - the CLI re-versioning the same-version service nupkg; - - `local_rebuild` from upstream; - - either of those produced by a different CLI version, where zip writer details change. -- **Consequence.** The §6.1 promise that one V′ equals one byte sequence everywhere is false for builder 1. - - In the feed tier on a shared runner GPF, the first writer wins. The second repo gets NU1403 on every locked restore on that runner. The research also verified that a failed locked restore still writes to the GPF, so the failure persists. - - Lockless projects silently use the other repo's bytes. `SOCKETPATCH002` catches this only if the table covers every consumed file. - - In the fallback tier the only cost is lock churn between developers. -- **Severity: major for the feed tier, minor for the fallback tier.** -- **Fix, any one of:** - - the feed tier requires builder 0 (service bytes) only; - - for local builds, derive N from the V′ nupkg's sha512 instead of the uuid, and record the uuid in state and in a nuspec field; - - freeze `reversion_nupkg` output with a cross-version golden, and forbid `local_rebuild` under builder 1 (give it a third code). - -### M5. Revert drift repair "from the signed-content-hash of a GPF copy" trusts a poisoned cache. -- **REASONED from the verified facts (first writer wins; the legacy layout wrote patched same-version bytes to `//`).** - - After legacy use, or on any shared or poisoned GPF, §7.4 step 1 computes the "upstream" hash from patched or tampered bytes and writes it into the committed lock under upstream V. - - The local locked restore then passes against the poisoned cache, which blesses it. CI either gets NU1403, or, if CI shares the cache, keeps the bad bytes. -- **Fix.** - - Repair only from depscan `upstreamContentHash`, or from a freshly downloaded nuget.org nupkg whose repository signature has been checked. - - Never repair from the GPF. If a GPF copy is used at all, require `.nupkg.metadata.source` to be nuget.org, a valid `.signature.p7s`, and `dotnet nuget verify` to pass. - -### M6. Provenance of the unpatched files is lost, and verify has no external anchor. -- **REASONED.** - - A normal restore checks nuget.org's repository signature on every extraction. - - Vendoring drops the signature once (it has to; NU3008). The fallback tier then never checks anything again (VERIFIED earlier: V-D9 and signing §b). - - For the unpatched members of the seed, integrity therefore rests on one HTTPS download on the vendoring machine. - - `verify` and `--check` compare state against seed against lock against targets. All of these are repo data. Only afterHashes (patched files only) come from the server. -- **Fix.** - - At vendor time, check the upstream nupkg's repository signature, or its sha512 against depscan `upstreamSha512` or the nuget.org catalog `packageHash`. - - Record `upstreamSha512` and afterHashes in state. - - `--check --online` (B1 fix 3) recomputes the full expected tree. - - Make depscan item #3 a GA requirement, not only a revert aid. - -### M7. Feed-tier trust: a repo-level, self-signed author trustedSigner applies to every package id. -- **DOCS and VERIFIED mechanics.** The signing research verified that trustedSigners merge across config levels and that `allowUntrustedRoot` passes `require`. NuGet documentation says `` trust has no `owners` or id scope. -- **Scenario.** Whoever holds the pfx (§10) can sign any package id, with any content, and it passes the enterprise's `require` in this repo. The design also normalises repos extending enterprise trust. A contributor could equally add their own fingerprint, and it would look like routine socket-patch churn. -- **Fix.** - - Generate an ephemeral key per uuid, sign, and destroy the private key before writing the fingerprint, so the trust covers exactly the bytes already signed. - - Better: never write trustedSigners. Print the `` block for the admin to add to machine-level config, or wait for depscan's CA-issued certificate with an RFC 3161 timestamp (item #8) and trust Socket's certificate once at org level. - - `vendor --check` flags any repo trustedSigner not recorded in state. - -### M8. Name handling: percent-decoding after validation allows path traversal; MSBuild metacharacters allow injection. -- **REASONED from the code.** - - `read_zip_members` (`crates/socket-patch-core/src/vendor/common.rs:336`) checks the **raw** name with `is_safe_relative_subpath`. §6.2 then percent-decodes. `%2E%2E%2Fx`, `lib%2F..%2F..%2Fx`, or `%5C` passes the raw check and decodes to traversal. Decoded names can also collide (`a%20b` and `a b`) or differ only in case. - - `is_plain_archive_name` allows `$ @ % ; ' ( )`. These are interpolated into `Include=`, `Condition=` and the `;path=hash;` `Contains` tables. `%XX` is unescaped by MSBuild, `;` splits items, `@(...)` and `$(Prop.Method())` are expanded. The result is a broken or forgeable inventory (a crafted name containing `=HASH;` can satisfy `Contains`) and property expansion at evaluation. - - `state.json` fields (id, versions, uuid, project paths) are rendered into the targets file by `regenerate_shared` straight from disk. -- **Fix.** - - Decode, then re-run `is_safe_relative_subpath`, `is_plain_archive_name` and `names_are_unambiguous`, case-folded. - - Refuse names containing `$ @ % ; ' = ( )`. Otherwise MSBuild-escape (`%24 %40 %25 %3B %27`) and XML-escape every interpolated value. - - Check id against `^[A-Za-z0-9_.-]+$`, versions against the parser, uuids against strict UUID format, and project paths on every render, not only in the prelude. - - Zip-bomb protection is already there (`MAX_ENTRIES`, per-entry and total caps enforced against the actual decompressed size). Reuse it and keep it. - -### M9. Guard coverage: packages without lib or ref assets are not checked at all. -- **REASONED.** - - `_SpCand` is built only from runtime, compile, native and resource items. For an analyzer-only or build-only package (source generators, SourceLink, MSBuild task packages), `_SpLocal` is empty. - - Then nothing is hashed, the `SocketPatchSeedFile` check is skipped (gated on `_SpLocal`), and `SOCKETPATCH003`/`005` never run. - - Even for lib packages, analyzers and `build/` files are not in `_SpCand`, although they run inside the compiler and MSBuild. -- **Fix.** - - Decide "patched package present" from the `project.assets.json` `libraries` and `targets` keys, not from asset items. - - Add `@(Analyzer)` to the candidates. - - Run the full-inventory check (B1) unconditionally at restore. - - Gate G1 on an analyzer-only fixture. - ---- - -## Minor - -- **m1. Symlinks (REASONED).** - - Committed symlinks inside the seed, or on its ancestors (`.socket`, `vendor`, `nuget`, ``), pass `SOCKETPATCH003`, because that check compares path strings without resolving symlinks. A seed linked outside the repo also opens a check-then-use race between hashing and compilation. - - Revert's "delete the seed and prune" through a symlinked ancestor deletes outside the repo. Rust's `remove_dir_all` does not follow a symlink passed as its own argument, but it does traverse symlinked ancestors in the path. - - Fix: apply the existing `refuse_symlinked`/`first_symlink` to the seed and all its ancestors in apply, verify and revert, and refuse non-regular files in the inventory walk. -- **m2. The signature policy is checked only at vendor time (REASONED).** A `require` added later to a repo, ancestor or user config is bypassed silently. The design documents only the CI-only case. Fix: `vendor --check` probes the policy again, and the restore-time target warns when it can see `signatureValidationMode` in `$(RestoreConfigFile)` or repo configs. -- **m3. Seed nuspec edits.** An added `` in the nuspec pulls in a new package. That is loud under locked mode (NU1004) and silent when lockless. B1's set-and-hash check at restore closes it. The current design only checks the nuspec after resolution, and only when `_SpLocal` is non-empty. -- **m4. Wording in §9.** "V′ present elsewhere → NU1403 when locked" holds only when the planted `.nupkg.metadata` hash differs (VERIFIED `x2`). The row should say that `SOCKETPATCH003`/`002` is the actual defence. -- **m5. Stale `obj/` (REASONED, low).** A pre-vendor `project.assets.json` followed by `build --no-restore` is caught by `SOCKETPATCH005`. After a revert, a stale assets file pointing at a deleted seed gives a loud missing-file error. Both are fine; keep them as test legs. -- **m6. Hash tables.** They depend on `GetFileHash` giving uppercase hex and on case-sensitive `String.Contains`. This works (VERIFIED `x0`: the metadata comparison passes, and editing `.nupkg.metadata` gives `SOCKETPATCH002`). Pin it with a golden test so a lowercase render never ships. - ---- - -## Verified experiment log - -| ID | Where | Result | -|---|---|---| -| x0 | `adv-integrity/x0` | Baseline passes: locked restore, `packageFolders` = GPF then the seed, guard `ok local=2`. The `SocketPatchSeedFile` hash check works: editing `.nupkg.metadata` gives `SOCKETPATCH002`. | -| x1 | `x1` | Tampered dll plus unlisted `build/*.props`/`.targets` in the seed: locked restore passes, the planted targets run, the guard is off, `Build succeeded`. With an unconditional `SocketPatchNuGetGuard=true` in our targets: `SOCKETPATCH002` fires, and a planted redefinition of the guard target is ignored. The `-pp` output shows the DBT imported after the package `build/*.targets`. | -| x2 | `x2` | V′ in the GPF with a copied `.nupkg.metadata` and other bytes: locked restore passes and resolves from the GPF, `SOCKETPATCH003` fires. Adding planted props that disable the guard: `Build succeeded` with the other bytes. | -| x3 | `x3` | A new nested `src/Directory.Build.targets` that does not chain: the new project builds upstream 13.0.1, a new lock is written, no error. The environment variable `SocketPatchNuGetGuard=false` hides a tampered seed. | -| x4/x5 | `x4`, `x5c` | `* text=auto` changes the hashes of the nuspec, LICENSE and xml members; `autocrlf=true` changes LF-only text members; the dll is unchanged. | - -## Priority fixes before the prototype is accepted -1. Restore-time full-set check of the seed, plus a CLI set-equality walk (B1). -2. Generated `.gitattributes` with `* -text -diff -merge -filter`, plus a `git check-attr` probe (B2). -3. Unconditional guard assignment and a CLI-managed allowlist (M1). -4. `vendor --check` evaluates every project for the import (M2) and supports `--online` rebuild verification (B1, M6). -5. A resolved-root check that also compares content hashes (M3). -6. Decode-then-validate names and escape MSBuild metacharacters (M8). -7. Candidates chosen from the assets file, including analyzers (M9). -8. Remove GPF-based drift repair (M5). -9. For the feed tier: builder 0 only, or content-derived V′ (M4), and no pfx-holder trust written at repo level (M7). \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/adversarial-lifecycle.md b/docs/design/nuget-vendoring-research/adversarial-lifecycle.md deleted file mode 100644 index 60883f9dd..000000000 --- a/docs/design/nuget-vendoring-research/adversarial-lifecycle.md +++ /dev/null @@ -1,305 +0,0 @@ -# Adversarial lifecycle review: NuGet vendoring v2 (unique-version fallback seed) - -## Verdict - -The build-time mechanism holds up: V′, the fallback folder, evaluation-time redirects and the guards. The weak part is the lifecycle, which the design does not specify well enough to implement. - -The design adds generated files shared by every NuGet entry: `socket-patch.targets`, `.gitignore`, and one DBT import per directory. It then tracks them with per-entry records, inside a CLI that: -- saves the ledger and sweeps old uuid dirs *after* the backend returns; -- drops cross-uuid wiring on re-vendor; -- keeps "preserved" entries byte-identical. - -Those three behaviours cause the two lifecycle blockers: -- **Patch update:** the most common lifecycle event breaks restore for every project in the repo. -- **Revert after an update, or reverting in the wrong order:** leaves an import to a deleted targets file. Restore then quietly rewrites locks to upstream. - -A third blocker is the git line-ending problem: under the common `* text=auto` rule, the committed seed does not survive a clone byte-for-byte. - -With the fixes below the design is still workable. §15 should grow by one structural piece: a pass that regenerates the shared NuGet outputs from the final ledger state. - -## Experiments run (SDK 8.0.131) - -All runs used an isolated `HOME`, `NUGET_PACKAGES`, `NUGET_HTTP_CACHE_PATH`, `TMPDIR` and `DOTNET_CLI_HOME`, under `/adv-lifecycle/`. Env script: `adv-lifecycle/env.sh`. The fixture is a copy of design-D `e1/r` (Lib, App, Tool; 13.0.1 and 12.0.1 redirected to `.1843260417`). - -| ID | Experiment | Result | -|---|---|---| -| **V1** | Cold GPF, then `dotnet restore S.sln --locked-mode` on the vendored repo | **VERIFIED.** Afterwards the GPF holds only `newtonsoft.json.bson/1.0.2`. It holds **no** `newtonsoft.json` at any version, because upstream 13.0.1 and 12.0.1 are never downloaded. `packageFolders` = [gpf, `.socket/vendor/nuget/packages`]. | -| **V2** | Add one non-existent uuid root to `RestoreAdditionalProjectFallbackFolders` | **VERIFIED.** `error NU1301: The local source '…' doesn't exist` for **every** project that imports the targets: Lib, App and Tool, including projects that do not use the patched package. | -| **V3** | Unguarded `Import` of `socket-patch.targets` with the targets file deleted | **VERIFIED.** A plain `dotnet restore` **succeeds without error**, because NuGet's restore evaluation ignores missing imports. It **rewrites `Lib/packages.lock.json` from `13.0.1.1843260417` back to upstream `13.0.1`**. Only `dotnet build` then fails with MSB4019. A later `--locked-mode` restore passes against the rewritten upstream lock. | -| **V4** | Commit the extracted seed in a repo with `.gitattributes` `* text=auto`, then `git clone` | **VERIFIED.** In the clone, `newtonsoft.json.nuspec`, `LICENSE.md` and `lib/*/Newtonsoft.Json.xml` have different sha256 (CRLF became LF). The vendoring machine's tree still reports clean. The dll and `.nupkg.metadata` are unchanged. The fix below is also VERIFIED under both `text=auto` and `core.autocrlf=true`: a nested `.socket/vendor/nuget/.gitattributes` containing `* -text -diff -merge -filter` gives byte-identical clones. | - -Everything else below is **REASONED**, from the code as cited or from the verified facts above. - -## Findings - -### B1. Patch update to a new uuid breaks every restore, pins a dead V′, and makes revert unrecoverable (BLOCKER) - -**Scenario.** Patch A (uuid `3f9a…`, 13.0.1 → V′a) is vendored. The manifest moves to patch B (new uuid) for the same purl, and the user runs `socket-patch vendor`. - -**What the code does** (`vendor.rs` `record_vendor_entry` :1020, `sweep_stale_artifact` :1073): -1. The backend runs while A's entry is **still in the ledger**. -2. The CLI then replaces the entry under the same key. -3. The CLI deletes A's uuid dir. - -**What goes wrong:** -- §7.1 step 5 renders the targets from "state on disk minus *this* uuid (B) plus this entry". So it renders **both** A and B: - - A's root stays in `RestoreAdditionalProjectFallbackFolders`; - - there are two `Update` redirects for the same declared 13.0.1, and the later one wins; - - SOCKETPATCH001 checks A's seed. -- After `sweep_stale_artifact` deletes A's dir, every project fails with NU1301 (V2) or SOCKETPATCH001. Nothing regenerates the targets after the sweep. -- `plan_closure` and `plan_lock_edits` look for entries that resolve to **V**. After A, every lock resolves to V′a, so B finds no closure and makes no lock edits (or refuses). The targets redirect to V′b while the locks pin V′a, which gives NU1004 in locked mode. -- If B does edit V′a → V′b, it records `original` = the V′a text. `carry_forward_wiring` (`state.rs:418`) fills an original **only when `original` is None**. So B's revert would restore V′a, a version whose seed is gone (NU1301 or NU1102). -- The prelude checks `vendor_nuget_duplicate_patch` and `vendor_nuget_version_collision` against A's entry for the same purl and may refuse the update outright. - -**Fix:** -- The shared-output render must exclude every entry with the same ledger key or basePurl as the entry being written. -- More robustly, regenerate `socket-patch.targets` and `.gitignore` in a CLI step that runs **after** `persist_vendor_entry`, `sweep_stale_artifact` and each revert's `save_state` (see P1). -- The closure planner and lock planner must treat any `resolved` that `parse_socket_nuget_version` decodes to (id, V) as "ours". For those entries they should record `original: None`, so that `carry_forward_wiring` fills in the true upstream original from A (the key `##` is uuid-agnostic, so the match works). -- Duplicate and collision checks must ignore the entry being replaced. -- Add a docker leg: vendor A, update to B, run a locked restore, revert, then `git diff --exit-code`. - -### B2. Import records are "reference-counted" per entry, but the ledger cannot hold them, leaving the repo unbuildable after revert (BLOCKER) - -**Scenario 1 (patch update, then revert).** B's apply finds the imports already present. `inject_import` returns None, so nothing is recorded. `carry_forward_wiring` performs its union **only when `prev.uuid == entry.uuid`** (`state.rs:461`), so A's `nuget_msbuild_import` records are dropped. When B is reverted: -- no import record remains; -- step 2 deletes the targets because no entries are left; -- every DBT still imports a missing file. - -**Scenario 2 (two ids, reverted in creation order).** Entries X and Y exist, and X created the imports. `vendor --revert` walks keys in sorted order and saves after each entry (`rollback.rs:891-902`). X is not last, so its import records vanish with X's ledger entry. Y has none, so the imports stay. - -**Scenario 3 (crash).** The process is killed between the import write and the ledger save. The next run sees the imports as pre-existing and has no record to undo them. - -**Outcome.** Every `dotnet build` fails with MSB4019. Worse, by V3 every plain `dotnet restore` (Dependabot, Renovate, `dotnet list package`, IDE restore) **silently rewrites the locks to upstream**. A bot PR can then commit unpatched locks. - -**Fix:** -- Stop tracking imports in per-entry records. -- Make import removal deterministic and free of records: on the last `nuget-fallback` revert, discover every DBT (same discovery as apply) and excise exactly the line carrying `Label="socket-patch"`. -- Delete a DBT only if its whole text equals `created_dbt(import_rel)`. -- Optionally keep a state-level `nugetShared` object (an additive optional field on `VendorState`) with the created and edited DBT originals, for byte-exact restore. -- **Order:** remove the imports first, and delete the targets only after every import is gone. If any excision drifts, write a no-op stub `socket-patch.targets` (just ``) rather than deleting it. - -### B3. The committed seed is not byte-stable through git (BLOCKER for Windows and VS-template repos) - -**Scenario.** The repo has `.gitattributes` `* text=auto` (the stock Visual Studio template), `core.autocrlf=true` on Windows, or an LFS rule such as `*.dll filter=lfs`. - -**Outcome (V4).** Every fresh clone or CI checkout has different bytes for the nuspec, xml docs and LICENSE. Then: -- the seed-inventory hash in the guard fails with SOCKETPATCH002 on **every build except the vendoring machine's**; -- `fallback_in_sync` never holds, so each `socket-patch vendor` rewrites the seed, and git hides this because it normalises; -- patched text members (content files, `build/*.targets`, `.ps1`) also fail afterHash verification; -- with LFS, clones without LFS get pointer files. - -The legacy layout is immune because a `.nupkg` is binary. So this is a regression specific to the new layout. - -**Fix:** -- Generate `.socket/vendor/nuget/.gitattributes` with `* -text -diff -merge -filter` (V4 verified that it fixes `text=auto` and autocrlf). -- After writing, probe with `git check-attr text filter eol` on each seed file, and refuse with `vendor_artifact_git_transformed` if any file is still transformed. -- Add `.gitattributes` to the reserved names (§11.4) and the hot-path render check. - -### M1. Preserved, kept or failed-save entries are re-wired by the next render (MAJOR) - -**Scenario.** One of: -- `rollback --preserve-state` or `remove --preserve-state`: `VendorRevertStep::Preserved` keeps the entry byte-identical (`rollback.rs:860-864`); -- drift-keep (`Kept`); -- `LedgerWriteFailed`. - -After that, any later NuGet vendor or revert, or even the hot path of a *different* entry ("targets byte-equal to a fresh render"), renders from all `nuget-fallback` entries. The supposedly reverted patch comes back into the targets. - -**Outcome:** -- Locked projects: NU1004, because their locks were restored to upstream. -- Lockless projects: silently patched again. -- If the seed was deleted: NU1301 for every project (V2). - -**Fix.** Render only the entries that are actually wired. Add `nuget.wired: bool`, or `unwiredAt`, to `NugetMeta`, and set it false on Preserved and Kept. Never render an entry whose seed directory is missing; emit a warning instead. - -### M2. Revert step order defeats drift-keep, and deletes the targets before import removal can fail (MAJOR) - -**Scenario.** §7.4 step 2 regenerates the targets **without** this uuid. Step 4 then keeps the seed only if "the live targets file still names the uuid". That can never be true at step 4, so drift-keep never fires. The seed is deleted while a drifted lock still pins V′. The result is NU1004 when locked, and a dangling V′ pin for any tool that reads the lock. - -Step 2 also deletes the targets before step 3 tries to excise the imports, which is the B2 failure mode. - -**Fix.** Use this order: -1. lock records; -2. compute keep = any drifted record whose live text still contains V′; -3. if keep, leave the uuid in the targets, keep the seed, and return `kept_artifact`; -4. otherwise remove imports (last entry only, per B2); -5. regenerate or delete the targets; -6. delete the seed. - -### M3. On a clean machine the package never counts as installed: repair, update and migration have no pristine source (MAJOR) - -**Scenario.** CI or a teammate's clone. V1 shows the GPF never holds upstream `newtonsoft.json/13.0.1` again after vendoring. With §7.5, the crawler skips the seed folders. The loop (`vendor.rs:1840-1910`) therefore sees the purl as missing, and what happens next depends on the case: -- **Same uuid:** `ledger_covers` returns true for a directory artifact with `sha256: ""` (`state.rs:293` checks existence only), so the source becomes `Deferred`. The `vend_installed!` `debug_assert!(PackageSource::Installed)` (`vendor.rs:171`) then panics in debug and test builds. In release, `installed_dir` is a hint path. This does exist for legacy with a cold GPF, but legacy's first restore repairs it; in fallback it is permanent. -- **New uuid (patch update), `repair` (service None, `repair_vendor.rs:1632`), or `--offline`:** there is no fetch rung, so `package_not_installed` and exit 1. A NuGet patch can then only be updated where the service is reachable, or after revert, restore and re-vendor. - -**Fix:** -- Add a NuGet pristine-fetch rung: nuget.org flatcontainer, `//..nupkg`. -- Verify it fail-closed against the upstream `contentHash` that the ledger already holds in each `nuget_lock_entry_v2` `original`. For signed packages, compute the signed-content hash (zip without `.signature.p7s`, signing §e) instead of hashing the file. -- Treat that fragment like npm's "ledger-recovered pre-vendor registry fragment". -- Replace the `debug_assert` for nuget-fallback entries. The fallback hot path must never read `installed_dir`. - -### M4. The hot path and `--check` fail on CI before restore, and the closure re-plan misreads its own output (MAJOR) - -**Scenario.** §7.2 requires the recomputed closure plan to match `nuget.projects`, and §7.1 refuses `vendor_nuget_unrestored` when a project has neither a lock nor an assets file. - -**Outcome:** -- On a fresh clone (no `obj/`), lockless projects have neither, so `socket-patch vendor` or `--check` refuses or reports "closure changed" on every CI run. -- Even with locks, the post-vendor lock resolves **V′**, not V. A `pin` project's entry has become `Direct`, so without V′-awareness it looks like `direct`. `auto-follow` is ambiguous in the same way. The re-plan then "re-keys" and churns the targets. - -**Fix:** -- Persist the plan in state and treat it as authoritative. -- Re-plan only from csproj and CPM text plus the locks, with decoded V′ counted as V. Missing assets for a project already in the plan is not a refusal. -- Keep `vendor_nuget_unrestored` only for **new** projects that the plan has not seen. - -### M5. Older binaries (v4.0.0 is released) corrupt fallback entries; the "flavor gate in the same PR" protects only v5+ (MAJOR) - -**Scenario.** A teammate, or a CI action pinned to v4, runs `socket-patch vendor --revert` or `vendor` on a repo with `nuget-fallback` entries. - -**v4 revert** (`nuget_feed.rs:772-873`): -- every kind is unknown, so each produces a `vendor_lock_entry_drifted` warning; -- drift-keep probes only single-segment wiring files for the literal `.socket/vendor/nuget/`; -- `Directory.Build.targets` contains only the targets path, so the probe finds nothing; -- the seed is deleted and the call reports success; -- `revert_vendor_entry` drops the entry; -- the targets and locks still reference the uuid, so NU1301 in every project (V2), with no ledger entry left. - -**v4 vendor:** `config_wired` is false (there is no `socket-patch-` in `nuget.config`), so v4 runs a full legacy apply on top. It: -- writes a `.nupkg` into the same uuid dir; -- adds a source and catch-all to `nuget.config`; -- rewrites the root lock; -- writes a legacy entry. Because the uuid is the same, `carry_forward_wiring` merges the fallback records into it, and that entry then routes to the legacy revert. - -`load_state` has no version gate (`state.rs:562-590`), so bumping `VENDOR_STATE_VERSION` does not help. - -**Fix:** -- In the root DBT, emit one comment per uuid: ``. v4's drift-keep then keeps the seed and the entry, which is fail-safe. This also fixes M6's liveness probe. -- In v5, route any entry that carries `nuget_lock_entry_v2` or `nuget_msbuild_import` records to the fallback backend, whatever its `flavor`. -- Detect and heal a legacy `socket-patch-` source that sits beside a fallback seed. -- Document the minimum version. - -### M6. VEX silently stops attesting fallback-vendored patches (MAJOR, missing from the §15 module table) - -**Scenario.** `vex/discover/nuget.rs` is driven entirely by `nuget.config` (source plus mapping). The vendored liveness probe list for nuget is `CONFIG_NAMES` (`vex/discover/mod.rs:1750`). `vendored_wiring_in_files` looks for the literal `.socket/vendor/nuget/`. - -The fallback entry's recorded files are the DBT (which has only the targets path) and the locks (which have only V′). The targets file uses `$(SocketPatchNuGetDir)`, which is not the literal string. So `vendored_wiring_live` returns false and the entry reads as dead. - -**Outcome.** VEX output drops the patch without any error. - -**Fix:** -- Add a fallback extractor: parse `socket-patch.targets` (uuid roots plus `Update`/`Include` V′) and every discovered lock (decode V′ to purl@V plus the uuid prefix). -- Add `.socket/vendor/nuget/socket-patch.targets` and the discovered locks to the nuget probe files. -- Spell the uuid dir literally in the targets, as a comment or in the SOCKETPATCH001 path. -- Set `artifact_rel` to the seed directory. -- Put all of this in prototype scope. - -### M7. Partial-failure unwind is unsafe for shared outputs and reused seeds (MAJOR) - -**Scenario:** -- §7.1 step 4 may *reuse* an existing, already committed seed, for example on a closure re-plan. The unwind for steps 5–8 then "deletes the seed". -- Step 5 overwrites the shared targets and `.gitignore`, which have no recorded original. -- A lock edit fails at project k of N, for example on an unparseable lock. - -**Outcome.** A committed seed can be deleted while the targets still name it (NU1301 everywhere, V2). Alternatively, the new targets file is left behind with only some locks edited, which gives NU1004. - -**Fix:** -- Snapshot the bytes of `socket-patch.targets`, `.gitignore` and `.gitattributes` before step 5, and restore them on unwind. -- Delete the seed only if this run created it. -- Stage all lock splices in memory and write them last, each by temp file and rename. Unwind must restore every written file. - -### M8. Migration from the legacy layout destroys its own pristine source and leaves the repo unpatched on refusal (MAJOR) - -**Scenario.** §11.1 runs the legacy revert (step 1) before the fallback apply (step 2). - -**Problems:** -- The legacy revert deletes the committed patched `.nupkg`, which is the only local copy of the patched bytes. -- On a legacy machine the GPF `newtonsoft.json/13.0.1/*.nupkg` is **the patched one**, extracted from our feed. `local_rebuild` would therefore apply the patch to already-patched bytes, and the before-hash gate fails. -- Any fallback-only refusal (`exact_dependency`, `dbt_disabled`, `unrestored`, `version_literal_unknown`) that fires after step 1 leaves the repo **unpatched**. - -**Fix:** -1. Run `fallback_prelude` and `plan_closure` first. -2. Materialise V′ with `reversion_nupkg(committed_legacy_nupkg)`, builder Local, and verify the afterHashes. -3. Only then revert the legacy wiring and write the fallback wiring, as one unit that can be unwound. -4. The migration must fail as a whole and leave legacy intact. - -### M9. Restore does not fail closed when the targets file is missing (MAJOR; contradicts §6.4) - -§6.4 says an unguarded import means "it never degrades silently to upstream". V3 shows otherwise: -- `dotnet restore` ignores the missing import and **rewrites the locks to upstream**; -- only build fails. - -Restore-only pipelines therefore produce unpatched locks without any error: Dependabot/Renovate lock refresh, `dotnet restore` Docker layers without `.socket/`, and `dotnet list package --vulnerable`. - -**Fix.** Update §6.4 and §9 to describe this accurately. Recommend `socket-patch vendor --check` as a required CI step, and document that lock diffs from V′ to V in bot PRs mean the patch was dropped. In Docker, the COPY step must include `.socket/vendor/nuget/` whenever it copies `Directory.Build.targets`. - -### M10. Transitive pins keep themselves alive and never disengage (MAJOR) - -**Scenario.** Tool pins `[12.0.1.N]` because Bson 1.0.2 pulls in 12.0.1. Later Bson is removed, or bumped to a version that needs 13.x. - -**Outcome:** -- **Bson removed:** the pin's condition (the project has no PackageReference for the id) still holds. Tool keeps a direct dependency on patched 12.0.1 indefinitely, and `Publish="true"` ships the dll. -- **Bson needs ≥ 13:** NU1605 against the exact pin. -- The in-use probe ("any lock resolves V′") is satisfied by our own pin, so gc never reclaims the entry. - -**Fix.** The in-use probe and `vendor --check` must ignore edges the tool created itself. A pin counts as in use only if some other package in the assets or lock `dependencies` still lists the id at a range V′ satisfies. Otherwise, report `vendor_nuget_pin_orphaned` and drop the pin on the next `vendor`. - -### M11. The layout choice does not persist, so repos end up with mixed layouts (MAJOR) - -**Scenario.** -- `--nuget-layout` defaults to `feed`. -- Only *existing* entries are sticky. -- The flag is threaded only into `dispatch_vendor_one` and the preflight. It is not on `scan --mode vendored`, `get --mode vendored` or `repair`. - -**Outcome.** A teammate or CI adding a new NuGet patch without the flag vendors it in the legacy layout. The repo then has both a `nuget.config` catch-all and fallback targets. This is untested, and legacy GPF poisoning returns for that id. - -**Fix.** Infer the layout: if any `nuget-fallback` entry exists, new entries use fallback. Or persist a `nugetLayout` optional top-level field in the state. Put the flag on `GlobalArgs`. - -### Minor findings - -| # | Scenario | Outcome | Fix | -|---|---|---|---| -| m1 | A user edits `socket-patch.targets`, for example to add `SocketPatchNuGetAllowUnpatched` or exclude a project | The next render overwrites the edit without warning | Store the render sha in state. If the on-disk file differs from the last render, warn `vendor_nuget_targets_edited` and refuse without `--force`. Provide a supported user hook: an optional `socket-patch.user.targets` imported last, plus per-project properties. | -| m2 | "Import into every nearest DBT" reaches git submodules, `dotnet new` template content (`PackageType=Template`), samples, or vendored third-party trees | Submodule edits cannot be committed from the superproject, so projects there resolve upstream silently. Templates ship a broken import to their consumers. | Limit to projects in the same git worktree (`git rev-parse --show-toplevel`). Skip template content. Warn `vendor_nuget_import_skipped`. | -| m3 | A new subdirectory is added later with its own DBT that does not chain to the parent | The targets are never imported, so SOCKETPATCH005 cannot fire and the project is silently unpatched. §4's claim that 005 covers new projects is only partly true. | Say so explicitly. Have `vendor --check` list uncovered projects, and make `--check` part of the recommended CI step. | -| m4 | Developers with and without service access (builder 0 vs 1), and Q4 | Different V′ for the same uuid. Lock and targets churn as soon as anyone runs `--force` or a re-plan. | Hot path accepts either builder for the same uuid. Never switch builders without an explicit `--nuget-rebuild-service`. | -| m5 | Dry run | Earlier entries in the run are not persisted, so the preview render leaves them out and understates the diff | Render from the in-memory run state. | -| m6 | Directory artifact with `sha256: ""` | `ledger_covers`, `list` and orphan labelling rely on existence only. The `path.rs` leaf parser expects a `.nupkg` leaf. | Add a `fileInventory`-based intact check for nuget-fallback artifacts, and a nested leaf parser. | -| m7 | NU1903 on V′ | VERIFIED during V1: `NU1903 … 12.0.1.1843260417 has a known high severity vulnerability`. This is the same as before the patch, but still a false positive once patched. Under `TreatWarningsAsErrors` or `NuGetAuditLevel` it fails the build. NuGetAuditSuppress is out of prototype scope. | Bring NuGetAuditSuppress into the prototype for NuGet ≥ 6.11, or document the gap. | - -## P1. Can the prototype (§15) be built in the current code structure? - -Only with CLI changes that §15 does not list. What is missing: - -1. **No per-ecosystem finalize hook.** Shared outputs derived from the whole ledger need a `vendor::nuget_fallback::sync_shared(cwd, &VendorState)` call after every ledger mutation: - - `run_vendor` after `persist_vendor_entry` and `sweep_stale_artifact`; - - `run_revert`, `rollback`, `remove` (`revert_vendor_entry` after `save_state`); - - `run_vendor_gc`, `repair`, and scan/get vendored. - - Doing this inside the backend is what causes B1 and M1. -2. **`carry_forward_wiring` contract.** - - The backend must emit `original: None` for lock entries already at a Socket V′. - - Import wiring must move out of per-entry records (B2). - - A new-uuid re-vendor unions nothing. -3. **Layout plumbing is more than two call sites.** - - `vendor::service_preflight` (`vendor/mod.rs:918`) is a public 6-argument function with no ledger access, so `layout_for(entry_flavor, …)` cannot be evaluated there without a signature change. - - `dispatch_vendor_one` has callers at `vendor.rs:2636` and `repair_vendor.rs:1632`, and is also reached through `vendor_records` from scan and get. The flag belongs on `GlobalArgs`. -4. `vend_installed!` `debug_assert` and a NuGet fetch rung (M3). -5. VEX discovery and liveness (M6), the in-use probe with self-edge exclusion (M10), and crawler skipping all have to be in scope. Otherwise `vex`, `gc` and `list` regress as soon as the flag is used. -6. A v4 hybrid-entry router plus the DBT uuid comment (M5). - -Scale: the core modules in the §15 table look sized correctly. The CLI and VEX work above probably adds another 30–40% and touches 6–8 more files. None of it conflicts with the backend and dispatch shape. - -## Recommended design edits (summary) - -1. Add §6.7 "Shared outputs": - - `sync_shared` after every ledger save; - - render only wired entries whose seed is present; - - record-free import excision, removing imports before the targets; - - a stub targets file on drift; - - a generated `.gitattributes` checked with `git check-attr`. -2. Add §7.6 "Patch update": - - V′-aware planner; - - `original: None` carry-forward; - - exclude the entry being replaced; - - a docker leg for update, revert and a clean diff. -3. Reorder §7.4 revert as in M2. Reorder §11.1 migration as in M8. -4. Correct §6.4 and §9 on restore behaviour when the targets file is missing (V3), and make `vendor --check` the documented CI gate. -5. Extend §15 scope: VEX, the in-use probe, the fetch rung, the v4 hybrid router, layout inference, and the finalize hook. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/adversarial-shapes.md b/docs/design/nuget-vendoring-research/adversarial-shapes.md deleted file mode 100644 index 6ed578546..000000000 --- a/docs/design/nuget-vendoring-research/adversarial-shapes.md +++ /dev/null @@ -1,161 +0,0 @@ -# Adversarial review: NuGet vendoring v2 (unique-version fallback seed), project shapes - -**Environment.** .NET SDK 8.0.131 on Linux, with HOME, NUGET_PACKAGES, NUGET_HTTP_CACHE_PATH, TMPDIR and DOTNET_CLI_HOME isolated per experiment. I ran one dotnet process at a time. - -**Where everything is.** Experiments are under `/adv-shapes/exp/e{1,2,3,5,7,8,9}`. The generator is `adv-shapes/gen.py`: it renders the §6.3 targets as the design wrote them (guard, SOCKETPATCH001, pack guard) using design-D's real seeds (`13.0.1.1843260417`, `12.0.1.1843260417`). Lock "after" states come from `restore --force-evaluate`, which is the ideal output the CLI's edits would have to match. - -**Labels.** VERIFIED means I ran it. REASONED means I did not. - -## What held up (VERIFIED) -- The §6.3 guard works as written, with no MSB4096 metadata errors. - - SOCKETPATCH002 fires on a tampered dll that is consumed, and on a tampered seed file that is not. - - SOCKETPATCH005 fires. - - `GetFileHash` keeps the custom `Sha256` metadata. -- SOCKETPATCH001 (`BeforeTargets=CollectPackageReferences`) fires in normal restore and in static-graph restore, with and without `--locked-mode`. That covers part of G4. -- CPM with transitive pinning on, under a static-graph `--locked-mode` restore, passes (part of G7). -- The pack range restore fixes both a direct CPM reference and a CentralTransitive pin: the nuspec says `13.0.1`. -- Package ids that differ only in case are redirected (`newtonsoft.JSON`). F# (`.fsproj`) works. GlobalPackageReference and nuget.g.targets are imported before DBT, so `Update` reaches them. - ---- - -## Blockers - -### B1. An exact `[V′]` spreads through ProjectReference and breaks projects the closure never sees (VERIFIED, e2) -**Setup.** Lib has Newtonsoft 13.0.1 (patched). Lib12 has 12.0.1 (patched). Lib3 has 13.0.3 (unpatched). -- AppA references Lib and Lib3. It resolved 13.0.3 before vendoring. -- AppB references Lib and Lib12. It resolved 13.0.1. -- AppC has a direct 13.0.3 reference and references Lib. - -**Results after vendoring:** -- **AppA:** `NU1107 Version conflict: AppA -> Lib -> Newtonsoft.Json (= 13.0.1.1843260417) / AppA -> Lib3 -> (>= 13.0.3)`. This is a hard restore failure. AppA is not in the closure, because it resolves 13.0.3, not V, so the prelude never checks it. -- **AppB:** `NU1107` between `(= 13.0.1.N)` and `(= 12.0.1.N)`. Patching two versions of one id breaks any project that reaches both. This is exactly the "multi-version of the same id" shape the design says is Supported. -- **AppC:** `NU1608` (Lib requires `= 13.0.1.N` but 13.0.3 resolved). This breaks the build under `TreatWarningsAsErrors`. -- **Locks outside the closure change too.** AppA's and AppC's `packages.lock.json` Project entries (`"Newtonsoft.Json": "[13.0.1, )"` → `"[13.0.1.N, 13.0.1.N]"`) change even though those projects are not in the closure. The CLI only edits locks in the closure, so AppC gets **`NU1004 ... references lib whose dependencies has changed`** in locked mode. - -**Fix (the range part is VERIFIED):** -1. Redirect to `[V′, )` instead of `[V′]`. After that change: - - AppA resolves 13.0.3, as before. - - AppB resolves 13.0.1.N (lowest applicable). - - AppC resolves 13.0.3, with no NU1608. - - Lib and Lib12 resolve V′. - - No NU1107. -2. Close the drift that `[V′, )` opens with a new guard, SOCKETPATCH006. Put a marker item (``) inside the same conditioned ItemGroup as the redirect. The guard fails if a project where the redirect engaged resolved the id at anything other than V′. Do not make NU1603 a repo-wide error: that would break existing builds that already have approximate matches on other packages. -3. The planner must edit the `Project`-entry range in **every** lock whose graph includes a redirected project, not only locks in the closure. Record each edit for revert. -4. Update the range-restore replace string to the `[V′, )` form. - -### B2. With chained nested DBT files, the once-guard imports the targets too early (VERIFIED, e7) -**Setup.** A common pattern: `src/Directory.Build.targets` imports the root DBT on its first line through `GetPathOfFileAbove`, then declares ``. - -**Why it breaks.** The root DBT's import runs first and sets `SocketPatchNuGetTargetsImported`. The import the design injects as the last child of `src/Directory.Build.targets` is then skipped. The redirect ItemGroup is therefore evaluated before the PackageReference exists. - -**Results:** -- Restore resolves **upstream 13.0.1**. -- The build fails with SOCKETPATCH005, so it is loud. In locked mode it fails NU1004 against the edited lock. -- When the project was planned as `pin`, the misfire is worse. The pin condition `@(PackageReference…)==''` is true at that point, so the pin is added next to the later Include. The result is `NU1504 Duplicate 'PackageReference'`, and the version that wins is arbitrary. - -**Fix (VERIFIED on SDK 8).** Stop injecting into DBT files. Put one line in the root, or nearest, `Directory.Build.props`: -```xml -$(CustomAfterDirectoryBuildTargets);$(MSBuildThisFileDirectory).socket/vendor/nuget/socket-patch.targets -``` -- `Microsoft.Common.targets:55` imports that property after the whole DBT chain, so ordering no longer matters. With this line the redirect applied and the build passed. -- It is also imported without the `ImportDirectoryBuildTargets` condition, so `vendor_nuget_dbt_disabled` becomes unnecessary. -- This needs a gating experiment on SDK 6 and 7 (MSBuild 17.0 to 17.7) to confirm the property exists there. - -### B3. Windows `core.autocrlf=true`, the Git for Windows default, breaks every build (VERIFIED by simulation, e1/clone) -**Cause.** An extracted seed contains text files: `.nuspec`, `lib/**/*.xml`, `LICENSE.md`, `.nupkg.metadata`, and content, build and props files. With `autocrlf=true`, git rewrites them to CRLF on checkout. - -**Result.** Every affected project fails with `SOCKETPATCH002 vendored NuGet seed file modified`. Today's layout commits a binary `.nupkg` and is immune, so this is a regression specific to the new layout. - -**Fix (VERIFIED: the clone builds).** Generate `.socket/vendor/nuget/.gitattributes` containing `* -text -diff -merge`, and treat it as a reserved name. Also decide how to handle a root `.gitattributes` that puts `*.dll` under git LFS: a clone without LFS gets pointer files and fails SOCKETPATCH002. Either add `-filter` or refuse with `vendor_artifact_lfs`. - ---- - -## Major - -### M1. A multi-target transitive pin is not conditioned on TFM (VERIFIED, e3) -**Setup.** ToolA targets `net8.0;netstandard2.0`. Bson is referenced only for netstandard2.0. - -**Result.** The §6.3 pin has no `$(TargetFramework)` condition. It adds `Newtonsoft.Json [12.0.1.N]` as a new **Direct** dependency to `net8.0`, which previously had `{}`. -- The CLI plans edits only for the TFMs where the id resolves, so locked mode fails NU1004. -- Lockless builds start shipping a new dll for net8.0. -- If the other TFM resolved a higher version, this becomes an NU1605 downgrade. - -**Fix.** -- Add `and '$(TargetFramework)' == ''` to each pin condition. -- Map aliases to lock keys. The lock uses `.NETStandard,Version=v2.0`, not `netstandard2.0` (VERIFIED), so this needs a real alias-to-framework mapping. Refuse custom aliases. - -### M2. A consumer outside the `.socket` root breaks, and the B1 fix would make it silent (VERIFIED, e8) -**Setup.** A project outside the root (a sibling repo, or a monorepo where `.socket` lives in a subdirectory) references the patched Lib through ProjectReference. - -**Results:** -- With `[V′]`: `NU1102 Unable to find Newtonsoft.Json (= 13.0.1.N)`. The consumer does not import the targets, so it has no fallback folder. -- With `[V′, )`: `NU1603` and a silent resolve of **13.0.2**. - -**Fix.** -- The planner walks ProjectReferences in both directions. It refuses (`vendor_nuget_external_consumer`) when a project outside the root references a redirected project, or when a redirected project is listed in a `.sln` or `.slnf` above the root. -- Document that `.socket` must sit at the root of the solution. - -### M3. SOCKETPATCH004 fires after the leaking `.nupkg` is already written (VERIFIED, e5) -**Result.** With range restore disabled, `dotnet pack -o out3` fails SOCKETPATCH004, but `out3/Lib.1.0.0.nupkg` already exists and has ``. PackTask writes the nuspec and the nupkg in the same step. A later `nuget push out/*.nupkg`, or a retry, publishes a package that consumers cannot restore. The "fail-closed" claim is false. - -**Fix.** -- Add a pre-check `BeforeTargets="GenerateNuspec"` against the rewritten pack assets. -- On a post-check failure, delete `@(NuGetPackOutput)` before raising the error. - -### M4. The pack guard fails with MSB4184 when `obj` holds more than one nuspec (VERIFIED, e5) -**Result.** Pack once, then again with `-p:Version=1.0.1`. `$(NuspecOutputAbsolutePath)*.nuspec` matches both `Lib.1.0.0.nuspec` and `Lib.1.0.1.nuspec`, and `ReadAllText("a;b")` fails the pack. Local and CI version bumps hit this routinely. - -**Fix.** Read exactly `$(NuspecOutputAbsolutePath)$(PackageId).$(PackageVersion).nuspec`, or filter `@(NuGetPackOutput)` by extension. - -### M5. The guard does not run for non-SDK csproj files that use PackageReference (REASONED; no mono here) -**Cause.** Legacy WPF and WinForms csproj files with PackageReference import DBT, so the redirect applies. They do not have `ResolvePackageAssets` or `RuntimeCopyLocalItems`, so SOCKETPATCH002, 003 and 005 silently never run. - -**Fix.** Detect a project with no `Sdk` that uses PackageReference, and refuse it or route it to legacy. Alternatively, hook `ResolveNuGetPackageAssets` and `@(ReferenceCopyLocalPaths)` and gate that on the Windows leg (G8). - -### M6. NuGetAudit still flags V′ (VERIFIED, e1) -**Result.** `warning NU1903: Package 'Newtonsoft.Json' 12.0.1.1843260417 has a known high severity vulnerability`. §2.3's "no false NU1903" holds only when the advisory's fixed version is V's own next patch. Here the fix is in 13.0.1, so `12.0.1.N` still falls inside `< 13.0.1`. -- Repos that treat NU1903 as an error stay broken after patching. -- NuGetAuditSuppress is out of the prototype's scope and needs NuGet 6.11 or later (SDK 8.0.4xx). The 8.0.1xx SDK here cannot use it. - -**Fix.** State the limitation in the design. Ship NuGetAuditSuppress with the prototype. On older SDKs, emit an informational `vendor_nuget_audit_still_flags`. - -### M7. The closure planner misses whole project types and version spellings (VERIFIED and REASONED) -- **VERIFIED (e9):** `Version="13.0.1.0"` means the same to NuGet as 13.0.1, but the literal redirect does not match it. The result is SOCKETPATCH005, and NU1004 if the CLI edited the lock. Render one condition per recorded literal spelling, or refuse the non-canonical spelling. -- **REASONED:** the enumerator looks only at `*.csproj|fsproj|vbproj`. It misses NoTargets and Traversal `.proj` files (from `global.json` `msbuild-sdks`), `.sqlproj`, `.esproj`, and others. They import DBT, so they get redirected with no lock edits. Enumerate `*.*proj` plus the projects listed in the sln. -- **REASONED:** property-expanded versions (Arcade `eng/Versions.props`) and `NuGetLockFilePath=$(MSBuildProjectDirectory)/…` depend on `dotnet msbuild -getItem`/`-getProperty`, which need MSBuild 17.8, i.e. SDK 8. Repos whose `global.json` pins SDK 6 or 7 get refused. Also, a `global.json` SDK that is not installed on the vendoring machine breaks every `dotnet msbuild` call. - ---- - -## Minor - -1. **The lock golden table is wrong for CPM with pinning on (VERIFIED, e5).** With the uniform `PackageVersion Update`, the entry stays `CentralTransitive` and only `requested` becomes `[V′, V′]`. It does not turn into Direct. -2. **Pin conversion reorders lock entries (VERIFIED, e3).** NuGet writes Direct entries first. Plain and locked restores do not rewrite a lock whose order differs, but `--force-evaluate`, Dependabot relocks, and the `--nuget-relock` text-diff check all see churn. Compare semantically, and write the canonical order. -3. **One tampered seed file fails every project (VERIFIED, e1).** The whole-inventory `SocketPatchSeedFile` hash made Tool, which only uses the 12.0.1 seed, fail for a tampered 13.0.1 seed. The cost also scales with the total seed size times the number of projects; think of native-heavy packages such as SkiaSharp. Filter on `PackageKey` for the packages this project resolved. -4. **An exact-bracket declared literal `[13.0.1]` is widened by pack range restore to `[13.0.1, )` (REASONED).** Render the replacement from the recorded literal. -5. **F# FSharp.Core and other implicit, SDK-versioned references drift across SDK versions (REASONED; props file checked).** Their version comes from the SDK that `global.json` resolves (`Microsoft.FSharp.NetSdk.props:95`). Refuse ids with `IsImplicitlyDefined`. -6. **The `vendor_nuget_tool_manifest` refusal is aimed at the wrong thing (REASONED).** `dotnet-tools.json` lists tool packages, and their dependencies are bundled inside those packages. MSBuild never resolves them. Say that tools cannot be patched, and keep the crawler from reporting that they are covered. -7. **RID lock sections list only packages with RID-specific assets (VERIFIED, e3/Rid).** Newtonsoft is absent from `net8.0/linux-x64`. RID edits matter only for packages that ship `runtimes/`. Add goldens for such a package, for example SqlClient. -8. **Windows MAX_PATH.** A 36-character uuid directory plus a long id plus a 4-part V′ is about 225 characters under `C:\agent\_work\1\s`. Use a short uuid8 directory. -9. **Analyzer-only packages are invisible to the guard (G1 still open).** - ---- - -## How the verdict changes - -The D base is sound for GPF safety, source mapping, and CPM with static-graph restore. It is **not** ready for its own "Supported" rows: -- multiple versions of one id; -- a patched library consumed next to a higher-versioned sibling; -- nested DBT chaining; -- multi-TFM transitive-only projects; -- Windows checkouts. - -**Minimum changes before prototype acceptance:** -1. `[V′, )` redirect plus SOCKETPATCH006. -2. Project-range edits in every lock that consumes a redirected project. -3. Injection through `CustomAfterDirectoryBuildTargets`. -4. TFM-conditioned pins. -5. The seed `.gitattributes`. -6. Pack guard pre-check, deletion of the bad nupkg, and an exact nuspec path. -7. The external-consumer refusal. - -Add e2, e3, e7 and the autocrlf clone as docker and e2e legs. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/code-map.md b/docs/design/nuget-vendoring-research/code-map.md deleted file mode 100644 index 3ef66df0b..000000000 --- a/docs/design/nuget-vendoring-research/code-map.md +++ /dev/null @@ -1,228 +0,0 @@ -# socket-patch NuGet implementation map (branch v5/nuget-vendoring, read-only) - -All paths are relative to `/home/user/socket-patch/crates/`. Where a line number carries a `~` it points to the right block but is not exact. - -## 1. Backend interface a new vendored layout must implement - -**There is no trait.** Backends are free functions with one shared signature. The CLI calls them through `match` arms. - -**Vendor entry** (the same 9 arguments for every backend), `socket-patch-core/src/vendor/nuget_feed.rs:399`: -```rust -pub async fn vendor_nuget(purl: &str, installed_dir: &Path, project_root: &Path, - record: &PatchRecord, sources: &PatchSources<'_>, vendored_at: &str, - dry_run: bool, force: bool, service: Option<&VendorServiceConfig>) -> VendorOutcome -``` - -**Revert entry**, `nuget_feed.rs:762` and `:772`: -```rust -pub async fn revert_nuget(entry: &VendorEntry, project_root: &Path, dry_run: bool) -> RevertOutcome -pub async fn revert_nuget_opts(entry: &VendorEntry, project_root: &Path, opts: RevertOpts) -> RevertOutcome -``` - -**Service preflight**, `nuget_feed.rs:372`: -```rust -pub(crate) async fn service_preflight(purl, project_root, record) -> Option -``` -- It must run the same refusal checks as `vendor_nuget`, so the download plan never asks the service for a package the loop will refuse. Today it shares `nuget_prelude` (`:243`) for this. -- It is routed from `vendor/mod.rs:918` (the nuget arm is at `:932`). - -**Dispatch points** in `socket-patch-cli/src/commands/vendor.rs`: -- `dispatch_vendor_one` (`:112`) uses the `vend_installed!` macro (`:168-190`). That macro asserts `PackageSource::Installed`, because NuGet and Maven have no registry-fetch rung. The nuget arm is at `:215`. -- `SERVICE_ECOSYSTEMS` includes nuget (`:135`). -- `dispatch_revert_one_opts` (`:237`), nuget arm at `:245`. -- `dispatch_in_use_one` (`:256`) returns `None` for nuget, so there is no in-use probe. - -**Types** -- `vendor/mod.rs`: - - `VendorWarning` `:142` - - `VendorServiceConfig` `:268` - - `VendorOutcome::{Refused{code,detail}, Done{result: ApplyResult, entry: Option, warnings}}` `:785` - - `RevertOpts{dry_run, keep_artifact}` `:801` - - `RevertOutcome{success, warnings, error, kept_artifact}` `:824` - - `force_apply_staged` `:732`, which applies the patch into a private stage and is hash-gated. -- `vendor/state.rs`: - - `VendorArtifact{path, sha256, size, platform_locked, file_inventory}` `:52` - - `WiringAction{Rewritten, Added}` `:83` - - `WiringRecord{file, kind, action, key, original, new}` `:97` - - `VendorEntry` `:212` - - `VendorState` `:324` - - `VENDOR_STATE_REL = ".socket/vendor/state.json"` `:43` - - `VENDOR_MARKER_FILE = "socket-patch.vendor.json"` `:764` - - `VendorEntry::committed_artifact_intact` (a sha256 check of file artifacts), right after `:212`. - -**Shared helpers to hook into** -- `vendor/common.rs`: `refused`, `done`, `already_patched_result`, `prepare_memory_repack`/`MemoryRepack`, `rebuild_zip`, `write_zip_entries`, `zip_bytes_match_after_hashes`, `any_live_file_references` (`:993`), `prune_empty_vendor_levels`. -- `vendor/path.rs`: - - `vendor_uuid_dir_rel("nuget", uuid)` - - leaf parser for `nuget` at `:280-286`, with `split_nuget_leaf` at `:207` - - ecosystem list at `:44` -- `vendor/ledger_snapshots.rs:56-62`: `WHOLE_FILE_KINDS` includes `"nuget_config_source"`. Whole-file values of 1024 bytes or more (`SNAPSHOT_MIN_BYTES`) are stored as diff ops, and those ledgers are written as version 2. -- `vendor/verify.rs:93-102, 488-498, 711`: `.nupkg` is treated as a single committed zip file, and its members are checked against the afterHashes. -- `vendor/reuse.rs:1-12`: the reuse path is for npm/pypi only. NuGet decides "in sync" from the committed artifact itself. -- `vendor/service_fetch.rs:155-240`: `service_archive_copy` returns `ServiceCopy::{Used, HardFail, FallBack}` (the Tier-A path). -- `socket-patch-cli/src/commands/repair_vendor.rs:105-129`: `WIRING_FILES` **does not include `nuget.config`** (see §7). - -## 2. Current on-disk layout, edits, state record and revert - -**Artifact** -- Path: `.socket/vendor/nuget//..nupkg` (`nupkg_leaf` `:172`, `normalize_nuget_version` `:125`). The normalizer mirrors the TS `normalizeNuGetVersion` and the two must stay in sync. -- Marker `socket-patch.vendor.json` is written beside it (`:664`). -- The uuid dir is the local folder feed itself (module doc `:8-18`). - -**Source key:** `socket-patch-` (prelude, around `:280`). - -**nuget.config** (`build_config_edit` `:1161`) -- Config lookup is root-only. `existing_config_path` (`:1145`) probes `nuget.config`, then `NuGet.Config`. It does not probe `NuGet.config`, although `nuget_config.rs:228` `CONFIG_NAMES` lists all three. -- **No config:** writes a fresh file (`:1171-1195`) containing the nuget.org source plus ours, and a mapping of `nuget.org → *` plus `socket → `. It is written to `project_root/nuget.config` (`:599`). -- **Existing config** (`:1196-1285`): - - Anchors are found on a comment-blanked view (`blank_comments` `:1292`). - - Our `` is inserted before ``. A self-closing `` is expanded (`:1390`), and if the section is missing it is created before ``. - - If `` exists, only our `` block is appended. - - Otherwise a new mapping is created that fans `*` out to every pre-existing source key (`parse_config_source_keys` `:1330`). nuget.org is seeded if there are none. - - It errors if there is no ``. - -**packages.lock.json** (`edit_lock` `:1545`) -- Only the root `project_root/packages.lock.json` is considered (`:93`). -- Every `dependencies..` entry (case-insensitive) whose `resolved` normalizes to the version (`locked_at` `:208`) gets `contentHash` replaced with `base64(sha512(nupkg))` (`content_hash` `:1116`). -- This is a string replace of the quoted old hash, so formatting is preserved. -- Entries that disagree on the hash cause a failure. An entry with no match gives the `vendor_nuget_lock_entry_absent` warning (`~:633`). A missing lock gives `vendor_nuget_no_lockfile` (`:653`). - -**Edit order:** artifact → config → lock. A failure in the lock step unwinds the config and deletes the uuid dir (`unwind_config` `:1641`, called around `:619` and `:646`). - -**state.json entry** (`nuget_entry` `:713`) -- Fields: `ecosystem:"nuget"`, `basePurl`, `uuid`, `artifact{path, sha256 (plain hex of the nupkg), size}`. All the extras (`lock`, `flavor`, `uv`, …) are `None`. -- The CLI adds `detached`/`record`. -- Wiring records, in application order (`:678-705`): - 1. `nuget_config_source`: `file` = the config basename; `Added` if we created the file, otherwise `Rewritten`; `key` = the source key; `original` = the whole pre-vendor file text (or none); `new` = the whole post-edit file text. This is the authoritative revert record. - 2. `nuget_config_mapping`: `Added`, `key` = the id, `new` = the mapping fragment. Audit only. - 3. `nuget_lock_entry`: `Rewritten`, `key` = the id, `original` = the old contentHash, `new` = the new one. -- Example: `socket-patch-cli/tests/fixtures/legacy-ledgers/nuget/wired/.socket/vendor/state.json`. - -**Hot path** (prelude, around `:318-345`; `vendor_nuget` `:437-535`) -- `config_wired` is a plain substring test: does the config text contain the source key? -- `in_sync` also requires the committed nupkg's members to match the afterHashes, and the lock to be pinned (or to have no matching entry). -- Wired and in sync: returns `AlreadyPatched` with no entry. -- Wired but stale: rebuilds only the artifact and re-pins the lock (with `original: None`; the CLI's `carry_forward_wiring` fills it in), and warns `vendor_artifact_rebuilt`. The config is never touched on this path. - -**Revert** (`revert_nuget_opts` `:772`) -- The uuid is validated first. -- Records are walked in reverse: - - Lock (`revert_lock_record` `:1606`): replaces our hash with the original. If ours is gone but the original is present, it counts as done. Otherwise it is drift. - - Mapping record: no-op. - - Config (`revert_config_record` `:1419`): - - The file name must be a safe single segment. - - If the live file is byte-identical to `new`: restore `original`, or delete the file if we created it. - - Otherwise: excise only our verbatim `` line and our `` block (`excise_source_mapping` `:1507`). - - If neither is present: drift (`Ok(false)`). - - The catch-all mapping is left in place. -- **Drift-keep** (`:844-860`): if any record drifted and a live wiring file still contains the uuid dir path, the artifact is kept (`kept_artifact`) so the exclusive mapping is not left pointing at a missing dir. -- Otherwise `remove_tree_and_prune` runs (`:871`). `keep_artifact` supports `--preserve-state`. - -## 3. Supported and refused project shapes - -**Explicit refusals** (prelude `:250-310`) -- Not a NuGet purl, non-canonical uuid, or id/version outside `[A-Za-z0-9._+-]` → `unsafe_coordinates`. -- Unreadable config → `vendor_nuget_config_unreadable`. -- Unreadable lock → `vendor_nuget_lock_unreadable`. -- No cached `.nupkg` → `vendor_nupkg_not_found` (`:962`). -- A config without `` → a failed result (not a refusal). - -**Everything else is accepted without detection:** - -| Shape | Handling today | -|---|---| -| **No lockfile** | Accepted with a warning. There is no content pin (`:653`; `docs/ecosystems.md:382-386`). | -| **Existing mapping** | Accepted. Our block is appended (`:1255-1260`). Nothing checks whether another source already maps the same exact id. NuGet then treats both sources as eligible, so the patched copy is not guaranteed. The vex doc lists this as a non-goal (`vex/discover/nuget.rs:59-65`). | -| **Multi-project / per-project locks** | Only the root `packages.lock.json` and root `nuget.config` are used (`:93`, `:1145`). Locks in sub-projects are never pinned. Parent-dir or user-level configs, ``, and custom `NuGetLockFilePath` are not handled (`vex/discover/nuget.rs:59-65`). The crawler reads `obj/project.assets.json` one level deep (`crawlers/nuget_crawler.rs:483-498`), but only to find package folders. | -| **CPM (`Directory.Packages.props`)** | Not referenced anywhere. No refusal and no special handling. A typical CPM solution keeps its locks per project, so it falls into the "no lockfile" warning path. | -| **packages.config** | Recognized as a .NET marker (`nuget_crawler.rs:419-436`), and the legacy `packages/./` dir is crawled. `vendor_nuget` accepts that dir as `installed_dir` (doc `:392-397`). No special handling and no test for restore under packages.config. | -| **Warm global cache** | Every real-restore test uses a cold `NUGET_PACKAGES` (`docker_e2e_vendor_nuget.rs:185-224`; `e2e_nuget_dotnet_build.rs` also uses a "cold `NUGET_PACKAGES`"). A same-id/version pristine copy already in `~/.nuget/packages` is untested. | - -## 4. How the patched .nupkg is built (`materialise_patched_nupkg` `:892`) - -1. **Service first.** `service_archive_copy(service, record, name, ".nupkg")` (`service_fetch.rs:169`). - - It POSTs `/v0/orgs/{slug}/patches/package` (or the public proxy's `/patch/package`) and GETs the grant URL (`api/client.rs:1106-1113`). - - The SRI is checked, and every member must hash to its afterHash, before the bytes are written verbatim. - - An integrity mismatch is always a hard failure. - - A miss under `auto` falls back to the local build. Under `--vendor-source=service` it is refused (`vendor_prebuilt_required`). -2. **Local rebuild** (`local_rebuild` `:949`). - - `locate_cached_nupkg(installed_dir)` (`:1123`) takes the first `*.nupkg` in the crawler's package dir. That is `~/.nuget/packages///` or `$NUGET_PACKAGES`, or the legacy `packages/./`. **The pristine bytes therefore come from the global packages folder** (or the legacy folder), never from a registry: NuGet has no fetch rung (`vendor.rs:168-170`). - - The in-memory repack (`prepare_memory_repack`, which also stages `.nupkg.metadata` and `*.nupkg.sha512`), then `force_apply_staged`, which also runs the sidecar fixup. - - Deterministic lexicographic re-zip that drops `.signature.p7s` (`rebuild_nupkg_bytes` `:1079`, `SIGNATURE_PART` `:108`). - - The upstream id and version are kept, with the same filename leaf. - -## 5. Hosted NuGet (`patch/redirect/mod.rs`) - -**Entry point:** `rewrite_nuget` (`:5317`), registered at `:449`. -- It reads only a root `nuget.config` (lowercase) and `packages.lock.json` (`scan/hosted.rs:75-76`, `mod.rs:5330`, `:5346`). If there is no config it starts from `default_nuget_config()` (`:5127`). -- An unparseable lock skips the whole NuGet rewrite (`redirect_nuget_lock_unparseable`). -- Per dep it requires a `nuget-v3` override and a sha512 (`:5362-5376`). - -**Config** -- `add_nuget_source` (`:5142`) adds ``. It seeds nuget.org when the new mapping would otherwise have no catch-all target. -- If there is no mapping, it creates socket-exact-id plus a `*` catch-all for each pre-existing source. If a mapping exists, it prepends only ours after ``. - -**Lock** -- For every framework entry whose id matches (**id only, not version**; `:5431`), it sets `resolved` = `nugetVersionNorm` and `contentHash` = the SRI with `sha512-` stripped. - -**URL form** (fixtures `socket-patch-core/tests/fixtures/redirect/nuget/packages-lock/{basic,empty-sources,empty-sources-selfclosing,no-preexisting-mapping}`): -- index: `https://patch.socket.dev/patch-registry/nuget///index.json` -- artifact: `…//flat///..nupkg` -- The data comes from `api_client.fetch_registry_references` (`scan/hosted.rs:1244`, `client.rs:748-776`, same POST `…/patches/package`). Integrity is taken from the reference's `tarball`-kind artifact (`hosted.rs:1281-1287`). - -**Why hosted revert is unsupported** -- The config `FileEdit` records only `new: {source, pattern}` with `original: None` (`:5413-5421`). No pre-edit snapshot exists, so it cannot be inverted. -- `replay.rs:181` classifies `redirect_nuget_source` and `redirect_nuget_lock` as `Inverse::Unsupported`; the module doc `:20-23` says these groups refuse with `hosted_revert_unsupported`. -- `takeover.rs:79-83` `redirect_revert_supported` covers only cargo, npm and golang. So vendored takeover of a hosted NuGet purl is also blocked (`vendor.rs:1585`, `:2416`), and `remove.rs:1359` reports `hosted_revert_unsupported`. -- The v5 plan (`docs/design/v5-plan.md` WS1) replaces this with a re-resolve from nuget v3. -- Hosted in-memory mode can't take inventory from NuGet either (`hosted_memory/roots.rs:51` `UNSUPPORTED_MARKERS`). - -## 6. Tests and how to run them - -Run everything from `/home/user/socket-patch`. - -| Test | Needs | Gate / command | -|---|---|---| -| Inline unit tests in `nuget_feed.rs` (from `:1662`, roughly 3.7k lines: config surgery, lock, revert, drift, hot path, service, tamper guards) | nothing | `cargo test -p socket-patch-core --lib nuget_feed` | -| `socket-patch-core/tests/covgap_vendor_nuget_feed.rs` (TMPDIR failure; `cfg(unix)`) | nothing | `cargo test -p socket-patch-core --test covgap_vendor_nuget_feed` | -| `crawler_nuget_e2e.rs`, `redirect_golden.rs` (shared TS goldens), redirect `mod.rs` tests `:7915+`, `replay.rs:3406` | nothing | `cargo test -p socket-patch-core` | -| `socket-patch-cli/tests/e2e_vex_lockfile/nuget.rs` (module in the `e2e_vex_lockfile` binary; hermetic, wiremock, no dotnet) | nothing | `cargo test -p socket-patch-cli --test e2e_vex_lockfile nuget` | -| `e2e_nuget.rs` (crawl only, wiremock proxy) | nothing | `#[ignore]` at `:182`, `:250`; run with `cargo test -p socket-patch-cli --test e2e_nuget -- --ignored` | -| `e2e_nuget_dotnet_build.rs` (hosted `:725` + vendored `:834`, real SDK, needs nuget.org) | host `dotnet` + network | `#[ignore]`; soft-skips without dotnet unless `SOCKET_PATCH_DOTNET_E2E_REQUIRED=1`; `SOCKET_PATCH_DOTNET_E2E_VERSION=8` picks the SDK; `cargo test -p socket-patch-cli --all-features --test e2e_nuget_dotnet_build -- --ignored` | -| `docker_e2e_nuget.rs` (apply chain, `:570`, `:607`) | Docker image `socket-patch-test-nuget:latest` | `#![cfg(feature="docker-e2e")]`; soft-skips if the image is missing (`:482`); `cargo test -p socket-patch-cli --features docker-e2e --test docker_e2e_nuget` | -| `docker_e2e_vendor_nuget.rs` (`:472`: 3-stage vendor → cold offline `--locked-mode` restore → RED/TAMPER(NU1403) → idempotence and revert) | Docker (SDK 8.0) | `--features docker-e2e --test docker_e2e_vendor_nuget` | -| `setup_matrix_nuget.rs` | host guard runs; `dotnet()` is `#[ignore]` (baseline gap) | `--features setup-e2e --test setup_matrix_nuget` | -| Other hermetic CLI tests (`in_process_get_hosted_ecosystems.rs:532`, `in_process_scan.rs:1374`, `in_process_rollback_all_ecosystems.rs:552`, `apply/e2e_safety_advisories.rs`, `ecosystem_dispatch_e2e.rs:310,986`, `vendor_ecosystem_fixtures/mod.rs:748`, `e2e_vex_vendor.rs`, `e2e_vendored_production.rs`) | nothing (production suites are canaries) | normal `cargo test -p socket-patch-cli --test ` | - -**Docker images:** build `tests/docker/Dockerfile.base` tagged `socket-patch-test-base:latest`, then `tests/docker/Dockerfile.nuget` (FROM `mcr.microsoft.com/dotnet/sdk:8.0`, copies the binary from base) tagged `socket-patch-test-nuget:latest`. - -**CI (`.github/workflows/ci.yml`)** -- `coverage-docker` (`:455`, matrix `:479`) and `e2e-docker` (`:1390`, matrix `:1398`) run `docker_e2e_nuget`, adding `docker_e2e_vendor_nuget` at `:561` and `:1447`. -- `e2e` (`:675`) runs `suite: e2e_nuget` (`:696`) and `e2e_nuget_dotnet_build` for dotnet 6/7/8/9/10 on ubuntu and 8 on macOS (`:1057-1064`, setup-dotnet at `:1248`, env at `:1351`). The default filter is `--ignored` (`:1353`). -- `setup-matrix` (`:1634`) is non-blocking. - -## 7. Known TODOs and limitations - -- `v5-plan.md:30-31`: "a better vendored story for … NuGet (… NuGet feed is fragile). Keep the current behavior; do not invest further now." -- There are no literal `TODO`/`FIXME` comments in the NuGet files. Documented non-goals are in `vex/discover/nuget.rs:59-65`: parent/user configs, per-project locks, ``, a non-Socket source that also maps the id, and `NuGetLockFilePath`. -- **Orphan-sweep gap.** `nuget.config` is missing from `repair_vendor.rs` `WIRING_FILES` (`:105-129`). That list feeds both `repair`'s ledger reconstruction and `sweep_orphan_vendor_dirs` (`vendor.rs:283-326`). Separately, the config names the uuid dir rather than a leaf file. Together this likely means repair cannot recover a NuGet entry, and the sweep could delete a NuGet uuid dir that is still wired. This comes from reading the code only; no test was run to confirm it. -- Config-name mismatch: vendor probes 2 spellings, vex/crawler probe 3, hosted probes only `nuget.config`. -- The hosted lock rewrite matches on id regardless of version (`redirect/mod.rs:5431`). -- The same id+version as upstream means the global-cache collision is untested (every test uses a cold `NUGET_PACKAGES`). -- The signature is dropped, so the package reads as unsigned. This relies on NuGet's default signature validation mode being `accept` (`:15-18`). -- Sidecar (agent mode): `patch/sidecars/nuget.rs:1-18` deletes `.nupkg.metadata` and only advises when `.nupkg.sha512` is present. -- `dispatch_in_use_one` has no NuGet probe (`vendor.rs:256-265`). - -## 8. The NuGet crawler (`socket-patch-core/src/crawlers/nuget_crawler.rs`) - -- **Global mode** (`:37-49`): uses `--global-prefix` if given, else `NUGET_PACKAGES`, else `~/.nuget/packages` (`nuget_home` `:392`). -- **Local mode** is gated by `is_dotnet_project(cwd)` (`:406`): a root entry that is `*.csproj`, `*.fsproj`, `*.vbproj`, `*.sln` or `*.slnx`, or `nuget.config` / `packages.config` in any casing. When the gate passes, paths are returned in this order: - 1. `/packages/` (legacy) - 2. the global cache - 3. the `packageFolders` keys of `obj/project.assets.json` in cwd and one level of subdirectories (`:472-512`) -- **Layouts** (`classify_package_entry` `:228`): - - Global: `//`, where the version must start with a digit (`:286-328`). - - Legacy: `./`, split at the first `.`+digit (`:453`). - - A package is verified by `lib/` or a `*.nuspec` (`:331`). -- It crawls **every package in those folders**. It does not filter by the project's dependency graph (it does not read assets targets or the lock). -- The purl comes from the directory name, which is lowercased in the global cache. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/critic.md b/docs/design/nuget-vendoring-research/critic.md deleted file mode 100644 index a1d8a80ef..000000000 --- a/docs/design/nuget-vendoring-research/critic.md +++ /dev/null @@ -1,84 +0,0 @@ -# NuGet vendoring research: critic pass (contradictions, verified gaps, open questions) - -I ran six experiments myself on SDK 8.0.131. Two results change the design: -- **A committed repo-local package folder only survives if it is set through `RestorePackagesPath`.** If it is set through `nuget.config` `globalPackagesFolder`, a user's `dotnet nuget locals --clear` deletes it. -- **Once a package is in that folder, NuGet never looks at sources or `packageSourceMapping` for it.** That makes the folder the only offline mechanism that does not depend on source mapping. The catch is that it also skips signature checks. - -Full notes are in `/research/critic/FINDINGS.md`, with the helpers (`env.sh`, `mkpatch.py`) and `seed/`, `tmpl/`, `exp/` next to it. In the text below, "package folder" means NuGet's global packages folder (normally `~/.nuget/packages`), and "seed" means a patched package pre-extracted into a repo-local package folder. - -**Isolation incident.** My first experiment ran `dotnet nuget locals all --clear` before I had set `TMPDIR`. It cleared the shared `/tmp/NuGetScratchroot`, which is NuGet's temp directory. A restore running in another agent at that moment could have failed. `env.sh` now sets `TMPDIR`, and every later experiment used it. - -## 1. Contradictions and tensions between reports - -1. **Option C, the repo-local package folder, conflicts with the signing report.** - - The shapes and lock-cache reports recommend seeding a repo-local package folder. - - The signing report verified that anything already extracted into a package folder skips signature validation, even under `signatureValidationMode=require`. It says this "quietly gets around enterprise policy; should not document it". - - Consequence: if we adopt option C, the tool itself has to check the effective signature policy. It should refuse, or require a Socket author signer, when the policy is `require`. It cannot rely on NuGet to enforce it. -2. **Which unique-version form to use.** - - The sources report recommends `X.Y.Z.N-socket.M`; the shapes and lock-cache reports recommend `X.Y.Z.N`. - - The trade-off: plain `X.Y.Z.N` collides with a real upstream 4-part version. The prerelease form never collides, but `pack` warns about it: **VERIFIED** `warning NU5104: A stable release of a package should not have a prerelease dependency` for `[13.0.3.1-socket.1]`, and no warning for `[13.0.3.1]`. - - Both forms leak into the nuspec of a packed library: **VERIFIED** `version="[13.0.3.1-socket.1]"` and `version="[13.0.3.1]"`. -3. **How serious NU3005 is.** - - The shapes report says keeping the signature "does not work" and cites NU3005. - - The lock-cache and signing reports verified that NU3005 is only a warning and the package installs as unsigned. - - Reconciled: a malformed signature entry means "treated as unsigned". It fails only under `require` (NU3004) or when warnings are treated as errors (DOCS). -4. **Whether NuGet trusts `.nupkg.sha512`.** - - The sources report says its content is ignored in a hierarchical feed; the lock-cache report says its text is copied when `.nupkg.metadata` is rebuilt for an unsigned package in the package folder. - - Both are correct, in different contexts. Either way the file is not a trust anchor. -5. **Implications across reports for today's code.** - - The code map says vendoring appends an exact-id mapping to our feed. The shapes report verified that id-wide mapping breaks every other version of that id in the repo (NU1102 for Tool's 12.0.1). So current vendoring likely breaks multi-version repos whenever `nuget.config` already has a mapping. - - The hosted lock rewrite matches on id regardless of version (`redirect/mod.rs:5431`). Combined with the shapes finding that one id resolves to different versions per project, this would rewrite the wrong versions' entries. -6. **Different bytes from the two build routes.** - - depscan repacks STORE-only; the local rebuild uses its own deterministic re-zip. The signing report verified that every layout change changes `contentHash`. - - So the service route and the local route give different lock pins. Verify and revert must hash the committed artifact, never a rebuild. - -## 2. DOCS claims worth verifying - -| Claim | Status | -|---|---| -| A dot-prefixed folder is excluded from SDK default globs (shapes) | **VERIFIED.** `.socket/nuget-packages/zz/1.0.0/Broken.cs` under a root-level csproj: `-getItem:Compile` lists only `Program.cs` and the build succeeds. Control: the same file in `pkgs-visible/` fails with `error CS1040`. | -| Local folder feeds are not HTTP-cached (lock-cache) | **VERIFIED (partial).** After restoring from a folder feed there are no newtonsoft entries in `NUGET_HTTP_CACHE_PATH`, and `.nupkg.metadata` `source` is the folder path. | -| An exact `[x]` dependency against a 4-part version gives NU1608 | Not verified. It needs a real package with an exact-version dependency. It matters for option B together with `TreatWarningsAsErrors`. | -| CPM allows one `PackageVersion` per id | Not verified. Cheap to check. | -| `require` mode has no per-package exemption; an untimestamped signature expires with its certificate | Not verified. The first is probably right given the NU3004 behaviour. | -| nuget.exe behaviour for packages.config | Unverifiable here (see §4). | - -## 3. Research topics nobody covered, and my results - -Of the topics on the list, only packages.config is still open (§4). The rest are covered at least partly. These next ones were not on the list; the first four are now answered: - -- **V1: `dotnet nuget locals --clear` against a committed seed.** - - With `RestorePackagesPath=$(MSBuildThisFileDirectory).socket/nuget-packages` in `Directory.Build.props`, `locals all --list` does not show the repo folder, and `--clear` leaves the seed in place. **VERIFIED** - - With `nuget.config` `` it printed `Clearing NuGet global packages folder: .../r/.socket/nuget-packages` and **deleted the committed seed**. **VERIFIED** - - Design rule: never point `globalPackagesFolder` in `nuget.config` at committed data. -- **V2: a seed bypasses sources and mapping.** - - The mapping mapped only `Humanizer.*` to nuget.org and left Newtonsoft.Json unmapped: restore succeeded, with no NU1100, from the seed. **VERIFIED** - - The only source was `./does-not-exist`, `obj/` was deleted, and `dotnet restore --locked-mode` printed `Restored ... (in 252 ms)`. `dotnet run` printed `{"a":1}` and the output dll ends with `SOCKETPATCHED`. **VERIFIED** - - This confirms the lock-cache claim that mapping is never consulted once a package is in the folder. -- **V2b: restore does not touch the seed.** `diff -r` of the seed before and after restore, build and run found no differences, so the git tree stays clean. **VERIFIED** -- **V3: dot-folder globbing.** See the table in §2. A repo-local folder under a root csproj must be dot-prefixed, or covered by `DefaultItemExcludes`. **VERIFIED** -- **Still uncovered:** - - `NuGetLockFilePath` and the `RestoreLockedMode` property - - static-graph restore (`RestoreUseStaticGraphEvaluation`) - - whether Visual Studio or nuget.exe honour `RestorePackagesPath` - - `dotnet test` with a repo-local folder - - macOS and Windows case-insensitivity for the seed path - - Dependabot/Renovate rewriting the version or lock - -## 4. Remaining unknowns - -- **packages.config.** A legacy csproj that imports `Microsoft.Common.targets` with a `packages.config`, run through `dotnet msbuild -t:restore -p:RestorePackagesConfig=true`, printed `Nothing to do. None of the projects specified contain packages to restore.` **VERIFIED.** DOCS: packages.config restore exists only in desktop MSBuild or nuget.exe. mono and nuget.exe are not installed, so it cannot be tested on this machine; it needs a Windows or mono CI leg. -- **CI overrides.** A CI job that passes `-p:RestorePackagesPath` or `--packages` bypasses the seed. With the upstream hash in the lock this silently gives an unpatched build; with the patched hash it fails with NU1403 (shapes, VERIFIED). There is no way to prevent it, only to fail closed. -- **Signature policy with a seed** (see §1.1). We would need a detection rule for an effective `require` policy across the user, machine and repo configs. -- **Pack leak for option B.** There is no verified mitigation other than limiting option B to non-packable projects or transitive `PrivateAssets=all` redirects. - -## 5. Implications for vendoring a patched package with the upstream id+version - -1. The id+version can stay the same **only inside a package folder the repo owns**: - - **Location:** `RestorePackagesPath=$(MSBuildThisFileDirectory).socket/nuget-packages`. Import it from an Exists-guarded `.socket` props file that is chained into every nearest `Directory.Build.props`. The folder must be dot-prefixed (V3) and must not be set through `nuget.config` (V1). - - **Seed contents:** `//` holding `.nupkg.metadata`, the lowercase nuspec and `lib/`. No `.nupkg` or `.sha512` is needed. Git sees no changes after a restore (V2b). - - **Lock pin:** put the patched hash in both `.nupkg.metadata` and every lock in the closure, so bypassing the folder fails closed with NU1403. - - **Cost:** every other package also downloads into the repo folder, so `.gitignore` needs negation rules for the seed. -2. With the seed in place, **no `nuget.config` edit is needed for the patched package** (V2). That removes the fragile source-mapping surgery, including the catch-all `*` and the multi-version NU1102 breakage. Revert is: delete the seed, restore the original lock hashes, and remove the props import. There is no global-cache eviction, because the shared package folder is never used. -3. The seed skips signature validation. The tool must detect an effective `signatureValidationMode=require` and refuse, or sign the package and document the `` signer entry. Otherwise the tool silently weakens the organisation's policy. -4. Any shared-cache variant, meaning today's folder feed plus mapping, cannot be made safe. All reports agree on this: the first copy written wins, the wrong copy leaks both ways, and NU1403 repeats until the entry is evicted. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/depscan.md b/docs/design/nuget-vendoring-research/depscan.md deleted file mode 100644 index cd26a6d4f..000000000 --- a/docs/design/nuget-vendoring-research/depscan.md +++ /dev/null @@ -1,204 +0,0 @@ -# depscan backend research for NuGet vendoring (for socket-patch v5) - -## TL;DR -- depscan already builds **one prebuilt patched `.nupkg` per patch**. It keeps the **same id and version as upstream**, repacks the zip STORE-only, strips `.signature.p7s` and adds no signature. The bytes are written once to object storage, and their **sha512 SRI** is saved as `package_integrity`. -- You can get it two ways: - - **Artifact route:** `/patch/nuget/...`. The vendoring service (`POST /v0/orgs/{org}/patches/package`) returns this URL, and socket-patch's `service_fetch.rs` already downloads and checks it. - - **Single-package NuGet v3 feed:** `/patch-registry/nuget/{token}/{uuid}/index.json`, used by hosted mode. -- **For unsigned packages, NuGet's `contentHash` is the base64 sha512 of the nupkg bytes.** That equals `package_integrity` with the `sha512-` prefix removed. A dotnet e2e test proves this. -- **A patched-version suffix exists for Maven (`-socket.`) and Go (`-socketpatch.`). NuGet has none.** NuGet is always served under the upstream id+version. -- **Nothing is signed anywhere.** `sign.ts` is an identity stub, and there is no key custody. -- **No NuGet-specific vendoring artifact exists server-side**, beyond the plain `.nupkg`. For comparison, gem has a stub gemspec, Go has the gopatch zip and npm has a berry zip. - ---- - -## 1. Hosted NuGet serving (patch-server) - -**Server entry:** `depscan/workspaces/patches/src/services/patch-serving/server.ts:65-80` registers three route families: -- `/patch/...`: `registerPatchServeRoute` in `serve-route.ts` -- `/patch-registry/...`: `registerPatchRegistryRoutes` in `registry-routes.ts:32`, one regex route that parses `req.path` -- `/gopatch/...` - -**URL grammar:** `depscan/workspaces/lib/src/socket-patch/patch-url.ts:1-23`. These parsers are shared by the server and SBOM recognition. -- Artifact URL: `https://{host}/patch/{eco}/{name}/{version}/{token}/{patch-uuid}/{filename}` (`parsePatchServeUrl`, :82) -- Registry URL: `https://{host}/patch-registry/{eco}/{token}/{patch-uuid}/` (`parsePatchRegistryUrl`, :156) -- Vendored path: `file:.socket/vendor/{eco}/{patch-uuid}/{leaf}` (`parseSocketVendorPath`, :253, a TS port of socket-patch `vendor/path.rs`) - -**NuGet v3 feed:** `nugetDecision` in `patch-serving/registry-decision.ts:361-427`. This is a pure function. It serves a feed containing exactly one package version, pinned by the uuid in the URL: - -| tail | response | -|---|---| -| `index.json` | Service index with only two resources: `PackageBaseAddress/3.0.0` → `{base}/flat/` and `RegistrationsBaseUrl/3.6.0` → `{base}/reg/` (:370-387). No search, autocomplete or catalog. | -| `flat/{idLower}/index.json` | `{versions:[verNorm]}` (:389-396) | -| `flat/{idLower}/{verNorm}/{idLower}.{verNorm}.nupkg` | Streams the object-store bytes with `ETag: ""` (:397-406) | -| `reg/{idLower}/index.json` | Minimal registration: one page, one leaf, with `catalogEntry:{id,version}` and `packageContent`. **No `packageHash`, no dependency groups, no `listed`** (:407-425) | - -**Gates, before any of the above** (`evaluateRegistryDecision`, :190-222): -- `unpublished_at` set → 410 -- ecosystem mismatch → 404 -- `package_status !== 'built'` → 408, or 404 if the build failed - -**Artifact headers:** `archive-response-headers.ts:11` -- `Cache-Control: public, max-age=3600, no-transform`, deliberately not `immutable`, so that revoking a grant still has an effect. -- There is no `X-Socket-Patch-Unsigned` header, although `sign.ts` suggests one. - -**Bytes served:** the output of `nugetRepacker` in `patches/src/repack/repackers/nuget.ts:35-69`: -- Unzips the upstream nupkg and substitutes the patched files. -- Leaves the nuspec, id and version unchanged. -- Removes `.signature.p7s` via `stripSignedArchiveMetadata` (`patches-shared/src/archive/repack-utils.ts:1290-1314`). -- Re-zips with `store: true`, level 0 (`repack-utils.ts:696-701`). -- The doc comment (:24-33) says unsigned output is the "current v1 contract". - -**Upstream fetch:** `patches/src/repack/upstream/nuget.ts:13-62`. -- Downloads from `api.nuget.org/v3-flatcontainer` using the lowercased id and normalized version. -- Does **not** verify against the registry `packageHash`. Per the comment at :49-59, only the per-file `before_sha` check applies. - -**Hash computation:** `patches/src/services/patch-package/build.ts:309-320`. -- Computes `sha512-` (`package_integrity`), sha256 (`package_blob_file_hash`), sha1 and md5 over the archive. -- Storage is write-once (:235-240); `gcs-store.ts:194-205` re-hashes on read-back. - -**Proof that `contentHash` equals `package_integrity` without the prefix:** `patches/src/test/integration/installers/nuget.installer.e2e.test.ts:1-36, 166-261`. -- Uses a real `dotnet restore` against a folder feed with ``. -- Runs `--locked-mode` with fresh `NUGET_PACKAGES` and `NUGET_HTTP_CACHE_PATH`. -- A negative leg swaps in the upstream package and expects NU1403. -- Note: the test isolates the global packages folder precisely **because** the same id+version collides in the global packages cache. - -## 2. Vendoring service contract (server ↔ client pairing) - -**Endpoint:** `POST /v0/orgs/{org_slug}/patches/package`, defined in `depscan/workspaces/api-v0/src/endpoints/orgs/patches/package.ts:252-258` (operationId `getPatchPackages`). -- **Request** (:37-42): `{uuids[], freeOnly}`. -- **Response** (:137-169): `results[uuid] = {status, url, purl, artifacts[], registryOverride}`. - - `status` is one of `granted | reused | pending_build | build_failed | withdrawn | forbidden | not_found`. - - `artifacts[].kind` is one of `tarball | yarn-berry-zip | gem-stub-gemspec` (:121-134). - - Integrity fields: `{sha512, sha256, sha1, md5, dirhashH1, goModH1, yarnBerry10c0}` (:46-62). - -**Public proxy:** `POST /patch/package` in `depscan/workspaces/patches-api-proxy/src/server.ts:1003-1030` forwards to the same endpoint and forces `freeOnly`. - -**Core logic:** `depscan/workspaces/app/src/patches/patch-package-references.ts` -- `getPatchPackageReferences` (:933). -- `buildPatchPackageArtifacts` (:469-530): the tarball comes first and carries sha512, sha256, sha1 and md5. For NuGet that is the only artifact; it points at the `/patch/nuget/...` serve URL. -- `buildRegistryOverride` for NuGet (:668-683) returns: - - `kind: 'nuget-v3'` - - `indexUrl: {base}/index.json` - - `nugetIdLower` and `nugetVersionNorm` - - **no hash** in the identifiers; the rewriter uses the artifact's sha512. - -**Client side (socket-patch):** - -| Step | File and lines | -|---|---| -| Choose endpoint: authenticated vs `/patch/package` proxy | `crates/socket-patch-core/src/api/client.rs:742-743`, `vendor_package_url` :1373-1386 | -| Two-step request, then download; `patch_server_url` rewrites the download host | `fetch_vendor_package` :1115-1160, `_once` :1242-1350 | -| Secondary artifacts | client.rs :1310-1348 | -| Checks the sha512 SRI floor (plus Go `h1:`) and fails closed on mismatch | `vendor/service_fetch.rs:88-138` (`fetch_verified_archive`) | -| Maven/NuGet path: service first, else local rebuild; `--vendor-source=service` hard-fails | `service_fetch.rs:170-200` (`service_archive_copy`) | -| NuGet vendoring calls it | `vendor/nuget_feed.rs:906` | -| Hosted-mode rewriter reads `nuget_id_lower` / `nuget_version_norm` | `patch/redirect/mod.rs:126-127, 449, 5126-5280` | - -The hosted-mode rewriter is mirrored in depscan: `depscan/workspaces/app/src/patches/registry-rewrite/nuget.ts:1-232`. It: -- adds a source plus a `packageSourceMapping`, with a catch-all for existing sources (:160-211); -- sets `contentHash` to the sha512 without the prefix and `resolved` to `nugetVersionNorm` (:69-112). - -**Answer to (2): yes, a prebuilt patched `.nupkg` is already available for vendoring.** socket-patch already consumes it through `service_fetch`. There is no NuGet-specific variant: no renamed or re-versioned build and no signed build. - -## 3. Patched-version suffix and distinct-identity precedents - -**Maven: `-socket.`** -- Derivation: `depscan/workspaces/app/src/patches/maven-suffix.ts:1-65`. `suffixMavenPom` rewrites the pom's `` and literalizes `${project.version}`, or returns null so the caller falls back to the same GAV. -- Serve: `registry-decision.ts:~430-470`. When the pom rewrite succeeds, the artifact is served only under the suffixed version and the bare-upstream paths return 404. There is deliberately no `maven-metadata.xml`, so version ranges cannot resolve it (fail-closed). -- The pom's sha256 is published as `mavenPomSha256` (`package.ts:93-101`) for a trusted-checksum pin. -- Note: the jar bytes themselves are not re-versioned; only the pom is. - -**Go: `-socketpatch.`, with the module re-homed to `patch.socket.dev/gopatch/`** -- `depscan/workspaces/lib/src/go/gopatch.ts:21-64`. -- `GopatchFlavor` (`repack/ecosystem-repacker.ts:65-80`) is a **second stored artifact** with its own sha512 and `h1:`, stored in `build.ts:395-405, 485-500`. -- Changed content must bump ``, never reuse a version (`build.ts:487-491`; `patch-sync/import-db.ts:56`). - -**Other secondary vendoring artifacts:** -- gem stub gemspec: `repackers/gem-stub-gemspec.ts`, stored in `build.ts:412-419`. -- npm yarn-berry cache zip: `build.ts:344-390`. - -**NuGet:** none. There is no `-socket.N` prerelease, no `+socket` metadata and no distinct id. `normalizeNuGetVersion` actually **drops** `+metadata` (`repack/nuget-version.ts:1-35`). That makes `+socket` useless as a distinguisher, because NuGet also ignores build metadata for identity and for the global packages cache path. - -**Other ecosystems' vendored artifacts server-side:** -- There is exactly one pipeline: the converter build in `services/patch-package/build.ts` feeding the `published_patches.package_*` columns (`queue.ts:410`), then the serve route. -- There is no separate "vendor" build; vendoring reuses the hosted tarball. - -## 4. NuGet identity in depscan - -**PURL:** `depscan/workspaces/lib/src/purl/schema/nuget.ts:1-25`. -- `pkg:nuget/@`, with no namespace. -- The name keeps its case (spec: case-sensitive in the archive, case-insensitive for lookup). -- `purl-full-name.ts:258-263` sets namespace to null. - -**Version normalization (three implementations kept in sync):** -- `patches/src/repack/nuget-version.ts:15-35`: lowercase, drop `+meta`, strip leading zeros, pad to 3 parts, drop a zero 4th part. -- `app/src/patches/patch-package-references.ts:555-590`. -- socket-patch `vendor/nuget_feed.rs`. - -Serve paths, the upstream fetch and `nugetVersionNorm` all use the normalized form. The serve decision checks the tail against the row using `idLower` and `verNorm`. - -**SBOM:** the pipeline NuGet tasks (`pipeline/src/task/cs/nuget/**`) have **no Socket-patch reference detection**. That detection exists for npm, pypi and gem only (grep of `detectSocketPatchReference`/`parseSocketVendorPath` in `pipeline/src`). A patched NuGet dependency therefore shows up as plain upstream `name@version`. If the NuGet package id or version changed, SBOM/purl mapping would need new detection. - -## 5. Signing - -- `patches/src/repack/sign.ts:1-38`: `defaultSign` returns null. -- The comments list a future `authenticode-p7s` kind for NuGet, but state "no key custody / KMS / HSM exists yet". -- Columns `package_signature` and `package_signature_kind` exist (`ecosystem-repacker.ts:55-62`; `queue.ts:410-411`) and are always null. -- There are **no repository or author signatures** for any ecosystem. -- Consequence: consumers using `signatureValidationMode=require` or `` will reject Socket nupkgs. The nuget repacker comment (:27-31) acknowledges this. - ---- - -## What could live server-side for NuGet vendoring - -1. **Keep today's prebuilt `.nupkg` and add the missing integrity pieces.** - - Feasibility: exists; the additions are trivial. - - The artifact and its sha512 are already served. `contentHash` is the sha512 payload of that artifact. - - Cheap additions: - - put `packageHash`/`packageHashAlgorithm` into the registration leaf in `registry-decision.ts:407-425`; - - add dependency groups taken from the nuspec so the registration is spec-complete. - - This does not remove the global-packages-cache collision. - -2. **A Socket-suffixed NuGet flavor, `-socket.` (prerelease), as a second artifact.** - - Feasibility: moderate. The Maven and Go flavors are close templates: `GopatchFlavor` storage in `build.ts:395-500`, and the fail-closed serve/404 pattern for bare paths in `mavenDecision`. - - Work required: - - rewrite `` in the nuspec; - - rename the entry `{id}.nuspec` and possibly rebuild `[Content_Types].xml`/`_rels`; - - the flat path, registration and `normalizeNuGetVersion` then handle the new version as-is; - - add `nugetSuffixedVersion` to `RegistryOverrideIdentifiers` and a new `artifacts[].kind` (for example `nupkg-socket`). - - Benefit: removes the global-packages-cache collision, source-mapping ambiguity and fall-through to nuget.org. - - Costs: - - a prerelease version changes resolution semantics: floating ranges ignore prereleases, NU5104 warnings appear, and transitive `>= x` constraints are still satisfied; - - the consumer must change `` or use central package management (CPM) / `Directory.Packages.props`; - - SBOM must learn to map `-socket.` back to the upstream purl (see §4). - - Using `+socket` metadata instead of a prerelease is **not viable**, because NuGet drops it for identity. - -3. **A distinct package id, e.g. `Socket.Patched.`.** - - Feasibility: low. - - Assembly and type identity would not change, but every transitive dependent still references the original id. It would need a shim or `PackageReference` aliasing that NuGet does not support. Not recommended. - -4. **Serve the vendored feed metadata server-side.** - - Feasibility: exists for hosted mode. - - The single-package v3 feed can be "ejected": socket-patch already gets the bytes. A local feed only needs the nupkg (a folder feed needs no metadata). Nothing extra is needed from the server. - -5. **Repository signature (`.signature.p7s`) with a Socket certificate.** - - Feasibility: not feasible now. There is no key custody (`sign.ts`). - - It would also make `contentHash` follow the signed-package rules, so it would no longer equal the plain sha512. The e2e test's claim would change. - -6. **Upstream `packageHash` recording, for the restore-upstream / revert of workstream WS1.** - - Feasibility: small to moderate. - - The server does not fetch or store the upstream nuget.org `packageHash` (`upstream/nuget.ts:49-59` skips it). - - Persisting the upstream sha512 and signed `contentHash` would let the CLI restore the original `packages.lock.json` entry offline. This addresses "hosted revert unsupported". - -7. **SBOM recognition of patched NuGet dependencies.** - - Feasibility: moderate. It does not exist today for NuGet. - - Needed if option 2 or 3 ships. It is useful even for same-version packages, via the `nuget.config` source URL or a `.socket/vendor/nuget/` path. - -**Items that do not exist anywhere in depscan:** -- a NuGet version suffix or distinct id; -- any signing; -- `packageHash` in the served registration; -- an upstream NuGet digest check; -- a vendoring-specific NuGet artifact; -- NuGet patch detection in SBOM. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/lock-cache.md b/docs/design/nuget-vendoring-research/lock-cache.md deleted file mode 100644 index 19a751416..000000000 --- a/docs/design/nuget-vendoring-research/lock-cache.md +++ /dev/null @@ -1,81 +0,0 @@ -# NuGet lock-file and package-cache research (SDK 8.0.131, Linux) - -Every experiment ran with its own fresh HOME, NUGET_PACKAGES and NUGET_HTTP_CACHE_PATH under `/research/lock-cache/exp//`. Full notes, commands and outputs are in `/research/lock-cache/FINDINGS.md`. The helper scripts (`env.sh`, `mkapp.sh`, `lockhash.sh`, `work/mkver.py`) and the test feeds are in the same directory. - -Terms used below: -- **GPF** is the global packages folder, normally `~/.nuget/packages`. -- **Patched** means a copy of Newtonsoft.Json 13.0.3 with bytes appended to `lib/net6.0/Newtonsoft.Json.dll` and a `SOCKET_PATCHED.txt` file added. -- **Upstream** means the unmodified package from nuget.org. - -## (a) What the lock file contains -- **VERIFIED:** For a signed package, `contentHash` is the base64 sha512 of the .nupkg with the `.signature.p7s` entry removed. It is not the hash of the file as downloaded. `zip -d t.nupkg .signature.p7s; openssl dgst -sha512 -binary t.nupkg | base64` gave `HrC5BXdl…`, which matches the lock file. The hash of the raw file is `mbJSvHfR…`, which is what the GPF's `newtonsoft.json.13.0.3.nupkg.sha512` holds. -- **VERIFIED:** For an unsigned package, `contentHash` is the sha512 of the file bytes (`hNLqr27u…` for the patched copy, both ways). -- **VERIFIED:** `.nupkg.metadata` in the GPF holds `{"version":2,"contentHash":,"source":}`. -- **VERIFIED** entry shapes: - - Direct: `{"type":"Direct","requested":"[13.0.3, )","resolved":"13.0.3","contentHash":…,"dependencies":{…}}` - - Transitive: `{"type":"Transitive","resolved","contentHash"}` - - Project: `{"type":"Project","dependencies":{"Humanizer.Core":"[2.14.1, )"}}`, with no hash - - CentralTransitive: `{"type":"CentralTransitive","requested":"[13.0.3.1, )",…}`. This needs Central Package Management with `CentralPackageTransitivePinningEnabled`. - -## (b) What restore does when hashes don't match -- **VERIFIED, cold cache:** Empty GPF, feed has the patched package, lock pins the upstream hash, `--locked-mode`. It fails with `error NU1403: Package content hash validation failed for Newtonsoft.Json.13.0.3. The package is different than the last restore.` But the patched package has already been fully extracted into the GPF, `.nupkg.metadata` included. **A failed restore still poisons the cache.** -- **VERIFIED:** GPF has upstream, lock pins patched, feed has patched: NU1403. Nothing is re-downloaded and the GPF is unchanged. -- **VERIFIED:** GPF has patched, lock pins upstream: NU1403. -- **VERIFIED, what NuGet compares against:** - - I left the upstream bytes in the GPF and edited only the `contentHash` in `.nupkg.metadata` to the patched hash. A locked restore against the patched lock **succeeded**. - - Editing only `.nupkg.sha512` still gave NU1403. - - So when a package is already in the GPF, NuGet compares the lock hash with the `.nupkg.metadata` value only. It never rehashes the .nupkg, the extracted files, or the feed bytes. -- **VERIFIED:** NU1403 also happens **without** `--locked-mode` whenever a `packages.lock.json` exists and its hash differs. -- **VERIFIED, other error codes:** - - NU1004: locked mode after a PackageReference changed (`The package references have changed for net8.0…`). - - NU1605: a direct reference to 13.0.3-socket.1 while a dependency needs >=13.0.3 (`Detected package downgrade: Newtonsoft.Json from 13.0.3 to 13.0.3-socket.1`). The SDK treats this warning as an error, yet the lock file was still rewritten. - - NU1102: the lock pins a version the feed doesn't have. -- **VERIFIED, signatures:** - - Keeping a stale signature that is well-formed and is the last zip entry gives `error NU3008: The package integrity check failed. The package has changed since it was signed.` - - A misplaced or malformed signature entry gives only `warning NU3005` and the restore continues. - - Signatures are checked only when a package is extracted, not when it is already in the GPF. - -## (c) The GPF never refreshes an existing package -- **VERIFIED:** I tampered with a dll inside the GPF. The locked restore passed and the tampered dll was used. -- **VERIFIED:** `.nupkg.metadata` is the marker that a package is complete. - - Delete it but keep `.sha512`: NuGet recreates `.nupkg.metadata` from the local files (`"source": null`) and does not re-extract. - - How it recreates the hash: for a signed package it recomputes the hash from the .nupkg; for an unsigned one it copies the text of `.sha512`. - - Delete both files: the package is downloaded and extracted again (the tampered dll went back to its original size). -- **VERIFIED:** `dotnet restore --no-cache --force --force-evaluate` does not refresh a GPF entry. -- **VERIFIED, stale copies leak both ways without a lock file:** - - After the failed restore above left the patched copy in the GPF, an unrelated nuget.org project with no lock file built against it (its output dll ends in `SOCKETPATCH`). - - The other way round: GPF has upstream, feed has patched, no lock. Restore quietly used upstream and wrote a lock with the upstream hash. - -## (d) Repo-local GPF -- **VERIFIED:** A relative `globalPackagesFolder` in nuget.config resolves relative to the nuget.config file, not the current directory. Restoring the solution from `src/app` created the folder at the solution root. -- **VERIFIED:** Restore, build and publish all used it (`project.assets.json` packageFolders and `NuGetPackageRoot` in `nuget.g.props`). `$HOME/.nuget/packages` was never created. `dotnet test` was not run. -- **VERIFIED, which setting wins:** `RestorePackagesPath` (MSBuild property) beats the `NUGET_PACKAGES` env var, which beats nuget.config. So a CI job that sets `NUGET_PACKAGES` overrides a nuget.config setting, but not a `Directory.Build.props` property. -- **VERIFIED:** A relative `RestorePackagesPath` in `Directory.Build.props` resolves per project directory, giving one GPF per project. Use `$(MSBuildThisFileDirectory)`. -- **DOCS:** The HTTP cache stays machine-wide. Local folder feeds are not HTTP-cached. - -## (e) Fallback folders -- **VERIFIED:** I pointed nuget.config's `` at a folder holding the extracted patched package. It was used in place and not copied to the GPF (the GPF stayed empty), and the built dll was the patched one. The lock hash came from the fallback's `.nupkg.metadata` and was byte-identical to the lock produced from a feed. -- **VERIFIED:** The minimum a fallback entry needs is `.nupkg.metadata`, the nuspec and `lib/`. It needs neither the .nupkg nor `.sha512`, and it worked with the only source pointing at a folder that doesn't exist. Without `.nupkg.metadata` the entry is ignored and NuGet goes to the source (NU1301). -- **VERIFIED:** An upstream lock against a patched fallback gives NU1403. The hash check only trusts the value written in `.nupkg.metadata`. -- **VERIFIED, the GPF beats fallback folders:** if the GPF already holds upstream 13.0.3, a patched lock fails with NU1403, and with no lock the upstream copy is used silently. A committed fallback folder is therefore not a vendoring mechanism on its own. It only works together with an isolated GPF. - -## (f) The lock doesn't record the source -- **VERIFIED:** A lock generated from nuget.org passed a locked restore from a local folder feed holding the same bytes, and the lock stayed byte-identical. The lock only pins id, version and contentHash. - -## (g) Version suffixes -- **VERIFIED:** `13.0.3+socket.1` collides completely with 13.0.3. - - The GPF path is `newtonsoft.json/13.0.3`, the lock says `resolved "13.0.3"`, and it says `requested "[13.0.3, )"` even when the csproj says `Version="13.0.3+socket.1"`. - - A second nuget.org project on the same GPF then built against the patched dll. -- **VERIFIED:** `13.0.3-socket.1` gets its own GPF folder, but it sorts below 13.0.3. That causes NU1605 whenever something needs >=13.0.3. -- **VERIFIED:** A four-part `13.0.3.1` gets its own GPF folder and sorts above 13.0.3, so there's no downgrade error. It works as a direct reference and as a CentralTransitive pin. -- **DOCS:** A dependency with an exact `[13.0.3]` range would give NU1608. A real upstream 13.0.3.1 would collide, but that's rare. - -## What this means for vendoring a patched copy with the same id+version as upstream -1. **A shared GPF can't be made safe.** The first copy written wins and is never refreshed. Patched bytes leak to other projects and CI caches, and upstream bytes leak in. A failed locked restore still leaves the wrong copy behind. -2. **The lock hash detects the problem but can't fix it.** It only compares against `.nupkg.metadata`. The only recovery is deleting that GPF entry, so hosted or cached-CI revert needs cache eviction as well as rewriting the lock. -3. **Robust options:** - - **(a) Repo-local GPF** set with `RestorePackagesPath=$(MSBuildThisFileDirectory)…` in `Directory.Build.props`. It beats `NUGET_PACKAGES` and covers restore, build and publish. It could be pre-seeded with the extracted patched package (a `.nupkg.metadata` file plus a minimal file set) and gitignore everything else. - - **(b) A distinct four-part version** such as 13.0.3.1, with Central Package Management transitive pinning. This removes the collision entirely. Don't use `+metadata` (it collides) or `-prerelease` (NU1605). - - **(c) A committed fallback folder.** It gives offline use without copying into the GPF, but only if the GPF doesn't already have that id+version, so it depends on (a). -4. **Always drop `.signature.p7s`** (otherwise NU3008). The patched package's lock hash is then just the sha512 of the rebuilt file, and the current rewrite of the lock `contentHash` must use that. -5. **The current design's catch-all `*` source mapping doesn't help.** Once the package is in any GPF, the mapping is never consulted. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/shapes.md b/docs/design/nuget-vendoring-research/shapes.md deleted file mode 100644 index 59802b458..000000000 --- a/docs/design/nuget-vendoring-research/shapes.md +++ /dev/null @@ -1,155 +0,0 @@ -# NuGet vendoring across project shapes: findings - -All tests ran on .NET SDK 8.0.131 on Linux. Each experiment had its own HOME, NUGET_PACKAGES and NUGET_HTTP_CACHE_PATH under `exp//`. Patched packages were built by `mkpatch.py`: it appends `SOCKETPATCHED` to the netstandard2.0 dll, adds `socket-patched.txt`, drops the signature and can rewrite the nuspec ``. - -The main test solution has three projects: -- **Lib** references Newtonsoft.Json 13.0.1 directly. -- **App** has a ProjectReference to Lib. -- **Tool** references Newtonsoft.Json.Bson 1.0.2, which pulls in Newtonsoft.Json ≥12.0.1, resolved as 12.0.1. - -Full notes are in `/research/shapes/FINDINGS.md`. The templates, `env.sh`, `mkpatch.py` and the feeds are in the same directory. - -## 1. Multi-project solution with PackageReference and lock files - -**VERIFIED:** each project's lock lists the package itself: -- Lib: `"type": "Direct", "requested": "[13.0.1, )"`. -- App: `"Transitive"`, with its own contentHash, plus a `lib` entry of `"type": "Project"` whose dependencies are `{"Newtonsoft.Json": "[13.0.1, )"}`. -- Tool: `Transitive 12.0.1`. - -So one package id shows up in every lock in the closure, and it can resolve to a different version in each project. - -**A (same id+version):** -- **Source mapping works per package id, not per version.** - - VERIFIED: once Newtonsoft.Json was mapped only to the local feed, Tool failed with `NU1102 Unable to find package Newtonsoft.Json with version (>= 12.0.1) … Versions from nuget.org were not considered`. - - Every version of that id used anywhere in the repo has to be in the local feed, or the id has to be mapped to both sources. - - VERIFIED: mapping to both worked 3 out of 3 times, and the local feed won each time. - - DOCS: which source wins when both hold the same version is not guaranteed. -- **Every project in the closure needs its lock contentHash rewritten.** - - VERIFIED: without it, Lib and App failed with `NU1403 Package content hash validation failed`. - - For an unsigned rebuilt package, contentHash = base64(sha512(nupkg)). VERIFIED: restore passed after rewriting it that way. -- **Global cache poisoning is fatal.** VERIFIED: with upstream 13.0.1 already in the global packages folder, restore failed with `NU1403`, even with `--force`. -- **No-op restore can hide the problem.** VERIFIED: with `obj/` left from an earlier good restore, restore did nothing and hid the poisoned cache. -- **The patched copy leaks into other repos.** VERIFIED: an unrelated project with no lock file, using only nuget.org and sharing the same cache, silently got the patched 13.0.1. -- **Keeping the original signature does not work.** VERIFIED: `NU3005 … signature file entry is invalid … compression method (8)`. -- **Pack is correct.** VERIFIED: the nuspec says `version="13.0.1"`, so there is no leak. - -**B (unique version):** -- **A prerelease suffix is ruled out.** - - VERIFIED: `-socket.1` sorts below the release. It triggered a false vulnerability warning, `NU1903 … 13.0.1-socket.1 has a known high severity vulnerability`. - - VERIFIED: next to a dependency that needs ≥12.0.1 it fails with `NU1605 Detected package downgrade: … from 12.0.1 to 12.0.1-socket.1`. -- **Build metadata does not create a new identity.** VERIFIED: `13.0.1+socket.1` is stripped and resolves as 13.0.1, which is the same as A. -- **A 4th version part works.** VERIFIED: `12.0.1.1` / `13.0.1.1` had no NU1605 and no false NU1903. -- **Metadata conditions must go inside a target.** VERIFIED: a `%(Version)` condition on an item Update outside a target fails with `MSB4191`. -- **Working repo-wide redirect, no csproj edits** (VERIFIED): - - `Directory.Build.targets` imports `.socket/vendor/nuget/socket.targets`. - - That file has a target with `BeforeTargets="CollectPackageReferences"`, which rewrites any PackageReference with `'%(Identity)'=='Newtonsoft.Json' and '%(Version)'=='13.0.1'` to `13.0.1.1`. - - Resulting locks: Lib Direct `[13.0.1.1, )`; App Transitive 13.0.1.1, with its `lib` project entry changed to `[13.0.1.1, )`; a project with a direct 13.0.3 is left alone. - - Then a `--locked-mode` restore with an empty cache passes, and build/publish output contains the patched dll. -- **Old locks fail and must be regenerated for the whole closure.** VERIFIED: `NU1004 The package reference … version has changed`, and on App `NU1004 The project references lib whose dependencies has changed`. -- **If the vendor feed is unusable, restore silently moves to a different version.** - - VERIFIED: with a ≥13.0.1.1 reference and the feed unmapped, NuGet picked 13.0.2 from nuget.org with only `NU1601 … ended up with Newtonsoft.Json 13.0.2`. - - VERIFIED: exact brackets `[13.0.1.1]` turn this into a hard `NU1102`. -- **`RestoreAdditionalProjectSources` only helps when the repo has no source mapping.** - - VERIFIED: set from an imported props file, it adds the feed without touching nuget.config. - - VERIFIED: when the repo has source mapping, that feed is used only if mapped by its **absolute path**. A relative key failed (NU1102). So nuget.config has to be edited anyway. -- **Pack leaks the new version to consumers.** - - VERIFIED: the nuspec gets `version="13.0.1.1"` (or `[13.0.1.1]` with brackets). - - VERIFIED: a consumer with an empty cache then fails with `NU1102`. Without brackets it would drift to 13.0.2 with NU1601. - - VERIFIED: a transitive redirect with PrivateAssets=all does not leak. - -**C (repo-local package folder):** -- **`RestorePackagesPath` in Directory.Build.props wins.** - - VERIFIED: `RestorePackagesPath=$(MSBuildThisFileDirectory).socket/nuget-packages` beat the NUGET_PACKAGES env var (the env cache stayed empty). - - VERIFIED: a pre-extracted patched `newtonsoft.json/13.0.1` was used as is; other packages were downloaded into the repo folder. -- **The seed can be minimal.** VERIFIED: `.nupkg.metadata` + nuspec + lib/ is enough; the .nupkg and .sha512 are not needed and NuGet does not re-hash the files. -- **The seed can carry the upstream hash, so the locks stay as they are.** VERIFIED: a `.nupkg.metadata` with the upstream contentHash, with locks untouched, passed `--locked-mode` and the patched dll was built. -- **It survives forced restores.** VERIFIED: `restore --force --no-cache` left the seed in place. -- **A CI override bypasses it.** - - VERIFIED: with `-p:RestorePackagesPath=…` and the upstream hash in the locks, restore silently downloads the unpatched package. - - VERIFIED: with the patched hash in the locks, it fails closed with NU1403. -- **Fallback folders are unsafe.** VERIFIED: `RestoreFallbackFolders` works with an empty cache, but if the cache already holds upstream 13.0.1, the cache wins and the result is silently unpatched. -- **Folder name and CI cost** (DOCS): a dot-prefixed folder is excluded from SDK default globs. Every package then lives in the repo, so a `.gitignore` with negation rules is needed and CI caching of the global folder stops helping. -- **Pack is correct.** VERIFIED: the nuspec says 13.0.1. - -## 2. Central Package Management - -- **Lock entry types** (VERIFIED): - - Transitive packages that have a PackageVersion appear as `"CentralTransitive"` even with pinning off. - - Tool showed `requested [13.0.1, )` but `resolved 12.0.1`. - - A project with a VersionOverride shows as Direct. -- **Turning pinning on changes nothing until locks are re-evaluated.** VERIFIED: with existing locks, both `--locked-mode` and a plain restore passed and kept Tool at 12.0.1. Only `--force-evaluate` moved it to 13.0.1. -- **Redirect without editing Directory.Packages.props** (VERIFIED): - - A `` in the imported targets file works. A non-matching version check did not redirect. - - Lib and App moved to 13.0.1.1. The VersionOverride project was untouched. - - Without pinning, Tool's requested range became `[13.0.1.1, )` but it still resolved 12.0.1. - - With pinning, Tool moved to 13.0.1.1. - - Old locks fail with `NU1004 Mistmatch between the requestedVersion of a lock file dependency marked as CentralTransitive…`. -- **Transitive-only project without pinning** (VERIFIED): - - Needs `` scoped to that project. - - `Version=` fails with `NU1008`. If the repo sets `CentralPackageVersionOverrideEnabled=false`, it fails with `NU1013`. -- **Pinning should not be the patch mechanism.** CPM allows one PackageVersion per id (DOCS). Turning pinning on changes other projects' versions: VERIFIED, Tool went from 12.0.1 to 13.0.1. -- **Answer to "only Directory.Packages.props?"** No. An imported targets file can do the redirect, but every lock in the closure still has to change. - -## 3. packages.config - -- **Not testable here.** VERIFIED: `which mono nuget` finds nothing. `dotnet restore` on the solution, on the csproj, and `msbuild -t:restore -p:RestorePackagesConfig=true` all print `Nothing to do. None of the projects specified contain packages to restore.` -- **How nuget.exe works** (DOCS): - - It restores to `/packages/./`, or to `repositoryPath` if set in nuget.config. - - There is no lock file and no contentHash; projects reference dlls through HintPath. - - It skips any folder that already holds `..nupkg`. -- **Verdicts:** - - C (pre-seed or commit the `packages/` folder) is the practical option. - - B needs every packages.config and HintPath edited. - - A with a folder feed works, but the packages/ folder poisons it the same way the global cache does. - -## 4. Directory.Build.props/targets injection - -- **Only the nearest file is imported.** - - VERIFIED: a nested `src/Directory.Build.props` hides the root one. - - VERIFIED: chaining with `$([MSBuild]::GetPathOfFileAbove(Directory.Build.props, $(MSBuildThisFileDirectory)..))` restores it. - - VERIFIED: the root .targets file is still found independently of the .props. - - So the injector must add its Import to the nearest existing file for every project. -- **A separate imported file works.** VERIFIED: an Exists-guarded `.socket/vendor/nuget/socket.props|targets` worked for all the properties and items above. -- **Limits outside MSBuild** (DOCS): source mapping can only be set in nuget.config. `Directory.Build.rsp` affects the msbuild CLI only. - -## 5. Transitive redirect - -VERIFIED: a per-project PackageReference with PrivateAssets=all (or VersionOverride under CPM) changes the lock entry from Transitive or CentralTransitive to Direct, with the new requested range. The parent's dependency line stays the same (Bson still lists `"Newtonsoft.Json": "12.0.1"`). No csproj edits are needed. - -## 6. Build, publish and pack - -- **Build and publish:** VERIFIED patched dll in the output for A, B (4th part) and C. -- **Pack:** VERIFIED A and C are correct. B leaks the new version into the nuspec whenever the package is a direct dependency of a packable project. - -## 7. Floating versions and ranges - -- **Resolution:** VERIFIED `13.0.*` and `13.*` resolve 13.0.4 today; `[13.0.1,14.0)` resolves 13.0.1. -- **Lock files win:** VERIFIED a plain restore with an existing lock keeps the locked versions. -- **4th-part versions are not picked up on their own:** VERIFIED 13.0.1.1 was not chosen for the range with `--force-evaluate`, so B has to replace the floating spec with the exact version. -- **A and C patch whatever the lock resolved:** DOCS/inferred, re-evaluating after upstream publishes a newer version silently drops the patch. - -## Verdicts - -| Shape | A (same version) | B (4th-part version + redirect) | C (repo-local packages folder) | -|---|---|---|---| -| Multi-project sln | Fragile: id-wide mapping, hash rewrite in every lock, cache poisoning and leaks to other repos | Works with the imported-targets redirect and exact brackets; locks must be regenerated; pack leaks | Works and is isolated from the global cache; a CI override bypasses it | -| CPM | Same as sln | Works with a PackageVersion Update; transitive-only projects need VersionOverride; the pinning trap | Works | -| packages.config | Poor | Heavy edits | Best (seed `packages/`) | -| Transitive-only | Automatic (id-based) | Per-project redirect, lock type becomes Direct | Automatic | -| pack/consumers | Correct | Leaks the new version | Correct | -| Floating/ranges | Tied to the lock | Must pin exactly | Tied to the lock | - -## What this means for a patched copy with the upstream id+version - -- **Same id+version is inherently unsafe in any shared cache.** Both the global packages folder and the packages/ folder are keyed on id/version alone. Every A failure seen here comes from that: NU1403 poisoning, silent leaks into other repos, per-id mapping breaking other versions. -- **The same identity is only safe in a cache the repo owns (C).** - - Recommended form: an Exists-guarded `RestorePackagesPath` import chained into every nearest Directory.Build.props. - - Seed a minimal extracted package. - - Write the patched contentHash into both `.nupkg.metadata` and the locks, so that bypassing the folder fails closed (NU1403) instead of silently restoring upstream. - - Do not use fallback folders. -- **If a unique version (B) is used:** - - Use a 4th version part, never a prerelease suffix or `+metadata`. - - Pin it with exact brackets. - - Apply the redirect through an imported targets file, not csproj edits. - - Regenerate the locks for the whole closure. - - Handle the pack leak, for example by limiting B to non-packable projects. \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/signing.md b/docs/design/nuget-vendoring-research/signing.md deleted file mode 100644 index 810aa2eff..000000000 --- a/docs/design/nuget-vendoring-research/signing.md +++ /dev/null @@ -1,102 +0,0 @@ -# NuGet signing and verification when vendoring a patched same-id+version nupkg - -**Headline:** once we change a package we have to drop its `.signature.p7s`. Keeping it fails restore with NU3008, even on Linux with no special settings. Dropping it works under the default policy but fails under `require` with NU3004. Signing, or not signing, never changes the lock `contentHash`. That means we can sign with a Socket certificate and keep lock pinning as it is. - -Setup: .NET SDK 8.0.131 on Linux. Each experiment had a fresh HOME, NUGET_PACKAGES and NUGET_HTTP_CACHE_PATH under `exp//`. The test package was Newtonsoft.Json 13.0.3 from nuget.org, which is author-signed and carries the nuget.org repository countersignature. The "patch" appends bytes to `lib/net6.0/Newtonsoft.Json.dll`. Restores used a single local folder feed (``) with `RestorePackagesWithLockFile`. - -## Environment -- **VERIFIED:** signature verification is on by default on Linux with SDK 8. `dotnet nuget verify` prints `X.509 certificate chain validation will use the fallback certificate bundle at '/usr/lib/dotnet/sdk/8.0.131/trustedroots/codesignctl.pem'`. A tampered signed package fails restore with no env var or config set. -- **VERIFIED:** the certificate revocation servers can't be reached from here. Genuine packages only get NU3018/NU3028 `RevocationStatusUnknown` warnings, even in `require` mode. -- **VERIFIED:** timestamp.digicert.com returns HTTP 403 through the proxy, so I could not test timestamped signing. - -## (a) Keeping vs dropping `.signature.p7s` (default mode, `accept`) -- **VERIFIED:** modified dll with the signature kept fails: `error NU3008: ... The package integrity check failed. The package has changed since it was signed.` -- **VERIFIED:** re-zipping with no content change and the signature kept also fails with NU3008. The signature covers the zip bytes, not just the file contents. -- **VERIFIED:** modified dll with the signature dropped installs cleanly, with no warnings. -- **VERIFIED:** `DOTNET_NUGET_SIGNATURE_VERIFICATION=false` turns verification off entirely. The tampered, still-signed package then installs. -- **VERIFIED:** if the signature entry has non-zero external file attributes (Python `zipfile` writes `0o600<<16` by default), restore only warns (`NU3005: The package signature file entry is invalid ... 'external file attributes' has an invalid value (25165824)`) and installs the package as if it were unsigned. - -## (b) `require` mode (enterprise setup) -The config was `signatureValidationMode=require` plus a `` entry with the three nuget.org repository certificate fingerprints (SHA256 `0E5F38F5…`, `5A2901D6…`, `1F4B311D…`). - -- **VERIFIED:** the genuine package installs even from a local folder feed. Repository trust is tied to the certificate, not the source URL. -- **VERIFIED:** the unsigned patched package fails: `error NU3004: ... signatureValidationMode is set to require, so packages are allowed only if signed by trusted signers; however, this package is unsigned.` -- **VERIFIED:** the patched package with the upstream signature kept fails with NU3008. -- **VERIFIED:** `DOTNET_NUGET_SIGNATURE_VERIFICATION=false` overrides `require`, and the unsigned package installs. -- **VERIFIED:** config precedence. With `require` in the user-level `~/.nuget/NuGet/NuGet.Config` and `accept` in the repo's `nuget.config`, the unsigned package installs, so a repo config can weaken the policy. With `require` at user level only, it fails with NU3004. -- **VERIFIED:** `trustedSigners` add up across config levels. The user level had `require` plus the nuget.org ``; the repo level added only an ``. Both the Socket-signed patched package and genuine nuget.org packages installed. -- **VERIFIED:** if the global packages folder already holds the extracted patched package, restore succeeds under `require` with no check at all. Signatures are only verified when a package is extracted into that folder. -- **DOCS:** `require` mode has no per-package or per-source exemption. `trustedSigners` entries are per certificate: an `` fingerprint, or a `` fingerprint with optional ``. `allowUntrustedRoot` only relaxes chain building for a listed certificate; it does not let unsigned packages through. - -## (c) Signing with a self-signed certificate (`dotnet nuget sign`) -I made the certificate with `openssl req -x509` (extended key use codeSigning, key use digitalSignature) and exported it to a pfx. - -- **VERIFIED:** signing works on Linux in about 1.1 s with exit code 0. `dotnet nuget sign moddrop.nupkg --certificate-path cert.pfx --certificate-password pw -o signed` warns NU3002 (no timestamper), NU3042 (root not in the codesignctl.pem bundle) and `NU3018: UntrustedRoot: self-signed certificate`. -- **VERIFIED:** restore results for the signed patched package: - -| Config | Result | -|---|---| -| Default `accept`, nothing trusted | Installs, with warnings NU3018 ("signing certificate is not trusted by the trust provider"), NU3027 (not timestamped) and NU3042 | -| `require` + `` fingerprint, `allowUntrustedRoot="false"` | `error NU3018` | -| `require` + `` fingerprint, `allowUntrustedRoot="true"` | Installs, only a NU3027 warning | -| `require`, no `` | `error NU3018` plus `error NU3034: This package is signed but not by a trusted signer` | - -- **VERIFIED:** re-signing a package that still has the upstream signature fails without `--overwrite` (`NU3001: The package already contains a signature`). With `--overwrite` it succeeds and installs under `require` with the author trusted. -- **VERIFIED:** `dotnet nuget sign` writes a valid signature entry even when the input zip has Python-style attributes. -- **VERIFIED (from `--help`):** the CLI can only create author signatures, so we cannot make a repository signature like nuget.org's. **DOCS:** repository signing exists only in the NuGet.Packaging API. -- **DOCS:** a signature without a timestamp stops being valid when the certificate expires. -- **Cost:** about a second per package, and no system trust store changes are needed. The user does have to add one `` entry with `allowUntrustedRoot="true"` if they use `require`. - -## (d) `dotnet nuget verify --all` (all VERIFIED) -- Unsigned: `error: NU3004: The package is not signed.` (exit 1) -- Modified with the upstream signature kept: prints `Signature type: Author` and `Signature type: Repository`, then `error: NU3008` (exit 1). -- Self-signed: `error: NU3018 ... not trusted by the trust provider` (exit 1). `--certificate-fingerprint` alone does not change that. With `--configfile` pointing at a config that has the `` entry, it exits 0 with only a NU3027 warning. -- Genuine: `Successfully verified package`, with revocation warnings. - -## (e) Global packages folder metadata and `contentHash` -- **VERIFIED:** the package's folder holds `.nupkg.metadata` (`{version:2, contentHash, source}`), `..nupkg.sha512`, a byte-identical copy of the nupkg, and an extracted `.signature.p7s`. The metadata records nothing about the signer. -- **VERIFIED: the lock `contentHash` does not depend on the signature file.** This corrects the assumption in the brief. - - For signed packages, `contentHash` is the SHA-512 of the archive with the `.signature.p7s` entry removed from both the file data and the central directory, and the end-of-archive record offsets and counts adjusted. My `signed_content_hash.py` reproduces the upstream `HrC5BXdl…zQ==` exactly. - - That differs from SHA-512 of the whole file (`mbJSvHfR…kg==`), which is what `.nupkg.sha512` stores. - - The unsigned patched package, the Socket-signed one and the re-signed one all produce the same `contentHash` (`Lb2f3WlJ…`), equal to SHA-512 of the unsigned file. - - `dotnet nuget sign` appends the signature and leaves every other byte unchanged. Swapping signed and unsigned files passes `--locked-mode`. -- **VERIFIED:** when the global packages folder already has upstream and the lock pins the patched hash, `--locked-mode` fails with `error NU1403: Package content hash validation failed`. Without a lock file, restore silently uses upstream and writes the upstream hash into the new lock. - -## (f) Zip layout and packaging metadata files (all VERIFIED; unsigned packages in `accept` mode all installed) -- These variants all restored fine: - - `.psmdcp` removed, even though `_rels/.rels` still points to it - - `_rels/.rels` and `.psmdcp` both removed - - `[Content_Types].xml` removed - - all three removed - - a new file with an extension not listed in `[Content_Types].xml` (`.patchmeta`, extracted to `lib/net6.0/`) - - entries in reverse order - - all entries stored without compression -- The version with all three files removed, then self-signed, installed under `require`. The console app built with `-m:1`, ran, and the copied dll ended with the patch marker. -- The global packages folder never contains `[Content_Types].xml`, `_rels` or `.psmdcp`. -- Every layout change produced a different `contentHash`, so the repack must be deterministic for the hash to be reproducible. -- **DOCS:** other tools that read these files the Office-document way (older `nuget.exe push`, Package Explorer) may still expect them. Keeping them, and adding a `Default` entry for any new extension, costs nothing. - -## Implications for each vendoring mechanism -1. **Same id+version, unsigned (current approach).** - - Works under `accept`. Always fails under `require` (NU3004), with no per-package exemption. - - The upstream `.signature.p7s` must always be removed (NU3008). A hand-written signature entry with non-zero attributes is silently treated as unsigned. - - The lock pin, plain SHA-512 of the file, is correct for unsigned packages. - - The main risk is a collision with an existing copy in the global packages folder (NU1403 in locked mode, silently using upstream otherwise). That comes from reusing id+version, not from signing. -2. **Same id+version, signed by Socket or a repo-local author certificate.** - - The lock hash is unaffected, and signing is cheap. - - Under `accept` the only cost is warnings: NU3018/NU3042 go away only if the certificate chains to a root in the SDK bundle, and NU3027 goes away only with a timestamp. - - Under `require` the user needs one `` entry with `allowUntrustedRoot="true"` for a self-signed certificate. It can go in the repo's `nuget.config` because it merges with the enterprise-level `trustedSigners`. This is the setup to document for enterprises. - - A self-signed or repo-local key is only as trustworthy as whoever can write to the repo. - - A CA-issued Socket code-signing certificate with a timestamp would remove `allowUntrustedRoot` and the warnings. Signing could happen on Socket's server, because the signature does not affect the lock hash. We cannot reproduce the nuget.org repository signature. -3. **Pre-filling the global packages folder or a fallback folder.** This skips verification even under `require`, which means it quietly gets around enterprise policy. We should not document it. -4. **A renamed id or new version (e.g. `13.0.3-socket.1`).** The signing situation is the same (unsigned fails NU3004 under `require` unless Socket-signed), but it removes the global-folder and lock collisions. This is inferred, not run. -5. **Overrides we should not recommend.** `DOTNET_NUGET_SIGNATURE_VERIFICATION=false` and a repo-level `signatureValidationMode=accept` both work, but both quietly weaken an organization's policy. The tool should detect an effective `require` and fail with a clear message pointing to the `` instruction. - -Everything is in `/research/signing/`: -- `FINDINGS.md` — full notes with commands and output -- `env.sh`, `run.sh` — setup and restore scripts -- `repack.py` — rebuilds the test packages -- `signed_content_hash.py` — the signed-package hash calculation -- `cert/` — the test certificate -- `v/`, `signed*/` — the package variants -- `exp//` — one folder per experiment \ No newline at end of file diff --git a/docs/design/nuget-vendoring-research/sources.md b/docs/design/nuget-vendoring-research/sources.md deleted file mode 100644 index dae0627e2..000000000 --- a/docs/design/nuget-vendoring-research/sources.md +++ /dev/null @@ -1,134 +0,0 @@ -# NuGet sources, packageSourceMapping and nuget.config research (SDK 8.0.131, NuGet 6.8.2) - -The tool harness refused to let me write `FINDINGS.md`, so the notes are below instead of in that file. The experiment dirs, helpers (`env.sh`), test packages and the delayed-HTTP feed server are under `/research/sources/` (in `exp/`, `pkgs/` and `httpfeed/server.py`). Every experiment ran with a fresh HOME, NUGET_PACKAGES, NUGET_HTTP_CACHE_PATH and DOTNET_CLI_HOME. - -To tell which bytes won, I read `gpf///SOCKET_PATCHED.txt` and the `source` field in `.nupkg.metadata`. "gpf" below means the global packages folder (`~/.nuget/packages`). - -**Command not available:** `dotnet nuget config paths` does not exist in 8.0.131. It fails with `error: Unrecognized command or argument 'config'` (VERIFIED). I used `dotnet restore -v:n` (the "NuGet Config files used" and "Feeds used" lines) and strace instead. - -## (a) Local folder feeds - -**Flat feed** -- A file named `.*.nupkg` resolves. The filename match is case-insensitive (`Newtonsoft.Json.13.0.3.nupkg`, lowercase and UPPERCASE all worked). Even `Newtonsoft.Json.13.0.3-whatever.nupkg` worked, because the version comes from the nuspec inside the package (VERIFIED). -- These fail with NU1101 (VERIFIED): - - `zzz-random.nupkg` - - `Newtonsoft.Json.nupkg` - - a nupkg in a subdirectory (the flat feed is not recursive) - -**Hierarchical feed (`//`)** (VERIFIED) -- It needs three files: - - the lowercase nupkg, - - `.nupkg.sha512`, which acts as the existence marker (nupkg + nuspec without it gives NU1101), - - `.nuspec` (nupkg + sha512 without it gives `error NU5037: The package is missing the required nuspec file`). -- **Linux needs lowercase.** A `Newtonsoft.Json/13.0.3/Newtonsoft.Json.13.0.3.nupkg` layout gives NU1101. -- **The `.sha512` content is not trusted.** I put garbage in it, and the gpf and lock contentHash still came out as the real SHA512 of the nupkg (`dkeh7b…`). NuGet re-hashes the package on install. -- **Dependencies come from the loose `.nuspec`, not the one inside the nupkg.** A loose nuspec with an extra dependency made restore pull Humanizer.Core. The nuspec extracted into gpf had no such dependency. So the loose nuspec must be byte-identical to the inner one. - -**`dotnet nuget push -s `** (VERIFIED) -- An empty dir gets a flat file, `Newtonsoft.Json.13.0.3.nupkg`. -- A dir that already has one full hierarchical entry (nupkg + nuspec + sha512) gets a full expanded entry: lowercase dirs, `.nupkg.sha512`, nuspec, `.nupkg.metadata` and all extracted files. It is not a `nuget add`-style minimal entry. - -**Performance:** a flat feed with 1 vs 201 `Newtonsoft.Json.*` files restored in 236–263 ms either way (VERIFIED). The difference doesn't matter at our scale. - -**Signatures** -- Keeping the original `.signature.p7s` on modified contents gives `error NU3008: The package integrity check failed. The package has changed since it was signed.` This happens even under the default `accept` mode (VERIFIED). The signature must be dropped. -- An unsigned package under `signatureValidationMode=require` gives `error NU3004 ... this package is unsigned` (VERIFIED). - -**Global packages folder poisoning** (VERIFIED) -- I restored upstream 13.0.3, then switched the config to only the patched feed and ran `restore --force`. There was no error, the gpf entry stayed upstream (`source: https://api.nuget.org/...`), and the assets file kept the upstream hash. A matching id+version in gpf means the feeds are never asked. -- With the patched contentHash in the lock file, `--locked-mode` gives `error NU1403: Package content hash validation failed ... different than the last restore`. Upstream was still written to gpf. After that, restoring with the patched feed also fails NU1403 until the gpf entry is deleted. - -## (b) packageSourceMapping - -**Exclusivity** (VERIFIED) -- Once any mapping exists, a package that no pattern matches fails: `error NU1100: Unable to resolve 'Humanizer.Core (>= 2.14.1)' ... PackageSourceMapping is enabled, the following source(s) were not considered: loc, nuget.org.` -- The catch-all is skipped for an id that a more specific pattern matches. With `nuget.org:*`, `loc:Newtonsoft.Json` and an empty loc, the result is `NU1101 ... No packages exist with this id in source(s): loc ... not considered: nuget.org`. There is no fallback. - -**Pattern precedence** (VERIFIED) -- The longest prefix wins: `Newtonsoft.Js*` on loc beats `Newtonsoft.*` on nuget.org. -- An exact id beats a prefix: `Newtonsoft.Json` on nuget.org beats `Newtonsoft.*` on loc. -- If the same pattern is on two sources, both are eligible. With loc empty it silently falls back to nuget.org; with both holding the package, it becomes the race described in (d). -- Pattern matching is case-insensitive. The source key is case-sensitive: a mapping for `LOC` against a source `loc` gives NU1100. - -**Missing or disabled source** (VERIFIED) -- A mapping to a key with no `` entry gives NU1100. -- A mapping to a source that exists but is disabled also gives NU1100. - -**Multiple config files** (VERIFIED) -- **A user-level mapping silently hides a repo source that has no mapping.** User `~/.nuget/NuGet/NuGet.Config` mapped `nuget.org:*`; the repo added `loc` with no mapping. Upstream was installed with no error. -- **Different keys combine across files.** User `nuget.org:*` plus repo `loc:Newtonsoft.Json` gave the patched package. -- **The same key in a nearer file replaces the farther file's patterns.** User `nuget.org:{*, Newtonsoft.Json}` plus repo `nuget.org:{Humanizer.*}` made Newtonsoft.Json fail NU1100. -- **`` inside `` drops the user-level mappings.** Anything the repo file doesn't map then fails NU1100. - -## (c) nuget.config precedence - -**Discovery** (VERIFIED, strace): NuGet probes `nuget.config`, `NuGet.config` and `NuGet.Config` in every ancestor directory up to `/`. It then reads: -- `$HOME/.nuget/NuGet/NuGet.Config` -- `$HOME/.nuget/NuGet/config/` (a directory of extra user-level configs) -- `/etc/opt/NuGet/Config/` (machine-wide) -- `/etc/opt/NuGet/NuGetDefaults.config` - -**File-name casing on Linux** (VERIFIED) -- `nuget.config`, `NuGet.config` and `NuGet.Config` all work. `NUGET.CONFIG` and `Nuget.Config` are ignored. -- If several are in one directory, only one is read, in the order `nuget.config` > `NuGet.config` > `NuGet.Config`. - -**Merging** (VERIFIED) -- Configs are merged and applied from farthest to nearest. -- `` in `packageSources` removes only sources from farther files. In the child it removes the parent's and the user's sources; in the parent it removes only the user's. -- A relative source value (`./feed`) resolves against the directory of the config file that declares it. - -**`--source` and `RestoreSources`** (VERIFIED) -- Both replace the configured sources, but the mapping still applies. -- A `--source` value equal to a configured source's value takes that source's key and mapping. -- An unconfigured path is named by its path, so it matches no mapping and fails NU1100 (`not considered: /other, nuget.org`). -- `-p:RestoreSources=` drops loc, so Newtonsoft.Json fails NU1100. - -## (d) Same id+version from two sources, no mapping (VERIFIED) -- **Local folder vs nuget.org:** the local folder won every time, in both config orders and with a cold or warm HTTP cache (4 runs each). -- **Two local folders:** the first-listed one won 6/6 times, and swapping the order flipped the result. -- **Local HTTP feed:** with 0 s delay it won in both orders. With 3 s delay it lost to nuget.org in both orders. - -Conclusion: the first source to respond wins, so the result depends on timing and is nondeterministic on real networks. - -## (e) RestoreAdditionalProjectSources in Directory.Build.props (VERIFIED) -- **With no mapping anywhere:** the source is added (it shows in "Feeds used") and joins the race. -- **With any mapping** (e.g. `nuget.org:*`): it is ignored and upstream is installed silently. -- **A mapping keyed by the absolute path works.** A relative value is named by its resolved absolute path, so a mapping keyed `feed` fails NU1100. This setup can't be committed portably. - -## (f) Giving the patched package a unique version - -**It resolves only from our feed** (VERIFIED) -- `13.0.3-socket.1` resolved from loc with no mapping. -- `13.0.3.1-socket.1` resolved from an HTTP feed with 3 s delay even though nuget.org was faster (restore took 9.95 s). There is no race when only one source has the version. - -**When our feed is missing** (VERIFIED) -- An exact `[13.0.3.1]` or `[13.0.3-socket.1]` gives `error NU1102: Unable to find package Newtonsoft.Json with version (= 13.0.3.1) - Found 0 version(s) in loc - Found 86 version(s) in nuget.org [ Nearest version: 13.0.4-beta1 ]`. -- A plain `13.0.3-socket.1` gives `warning NU1603 ... approximate best match of Newtonsoft.Json 13.0.3 was resolved` (upstream, silently). -- A plain `13.0.3.1` gives NU1603 and resolves upstream **13.0.4**. - -**Interaction with other packages' dependency ranges** (VERIFIED) -- A dependency asking `>=13.0.1` plus a direct `13.0.3-socket.1` is fine. -- A dependency asking `>=13.0.3` plus a direct `13.0.3-socket.1` gives `error NU1605: Warning As Error: Detected package downgrade: Newtonsoft.Json from 13.0.3 to 13.0.3-socket.1`. A prerelease sorts below its base version. -- A dependency asking `>=13.0.3` works with a direct `13.0.3.1` and with `13.0.3.1-socket.1`. The latter sorts above 13.0.3 and below 13.0.4, and also below any future upstream 13.0.3.1. -- `13.0.3+socket.1` (build metadata) is treated as 13.0.3 and came from nuget.org, so it is useless. - -**Transitive-only use needs a pin** (VERIFIED) -- If only a dependency references it (`>=13.0.1`), restore picks upstream 13.0.1. -- Central Package Management works: `ManagePackageVersionsCentrally` + `CentralPackageTransitivePinningEnabled` + `PackageVersion 13.0.3.1-socket.1` gave the patched package with no direct reference. - -**No cache collision:** the unique version gets its own gpf dir (`newtonsoft.json/13.0.3.1-socket.1`), so it can't collide with a cached upstream 13.0.3 (VERIFIED). - -## What this means for vendoring a patched copy with the same id+version - -1. **Same id+version can't be made robust.** - - gpf wins silently, even with `--force` (VERIFIED). - - A poisoned gpf, CI cache or shared runner gives permanent NU1403 or silent unpatched builds (VERIFIED). - - Without a mapping the winner is timing-dependent (VERIFIED). - - A mapping can be undone by a user-level, CI or ancestor-dir config: an unmapped repo source, a replaced pattern list for the same key, ``, or `--source` / `RestoreSources` (all VERIFIED). - - The current catch-all `*` workaround turns every package no pattern matches into an NU1100 risk once another config adds its own mapping. -2. **A unique version is deterministic** and needs no `packageSourceMapping`. Use `X.Y.Z.N-socket.M` (4-part base plus prerelease tag), not `X.Y.Z-socket.N` (NU1605 against any `>=X.Y.Z` dependency) and not `+meta` (same identity as upstream). - - Reference it with an exact bracket `[v]` (via `Directory.Packages.props` with transitive pinning, or a direct PackageReference), so a missing vendor dir fails hard with NU1102 instead of the NU1603 silent upgrade to upstream (VERIFIED). - - Revert is just restoring the original version string; no gpf cleanup is needed. - - Trade-offs (DOCS/inference): the lock file changes version and contentHash, and packable libraries would publish a dependency on a version consumers can't get. -3. **Feed format:** prefer a flat folder with `..nupkg`, which needs no sidecar files (VERIFIED). A hierarchical feed needs a lowercase path, a `.sha512` marker (its content is ignored) and a loose nuspec byte-identical to the inner one (VERIFIED). Declare the feed with a relative path in a lowercase `nuget.config` at the repo root (VERIFIED). Don't use `RestoreAdditionalProjectSources` (VERIFIED). -4. **Signatures:** always strip `.signature.p7s` (NU3008 otherwise). Repos using `signatureValidationMode=require` will reject any rebuilt package (NU3004), so detect that and refuse. \ No newline at end of file diff --git a/docs/design/nuget-vendoring.md b/docs/design/nuget-vendoring.md deleted file mode 100644 index 67c3f3299..000000000 --- a/docs/design/nuget-vendoring.md +++ /dev/null @@ -1,914 +0,0 @@ -# NuGet vendoring v2: unique-version fallback seed - -**Status:** draft, revision 3. Revision 2 added the four adversarial reviews (§16). Revision 3 records where the prototype overrides the design (§0). Vendored NuGet redesign stays future work for v5 (see `v5-plan.md`). This document lands on its own; the prototype code lives on the branch [`v5/nuget-vendoring-prototype`](https://github.com/SocketDev/socket-patch/tree/v5/nuget-vendoring-prototype) and is not merged. - ---- - -## 0. Where the prototype overrides this design - -The prototype on the branch [`v5/nuget-vendoring-prototype`](https://github.com/SocketDev/socket-patch/tree/v5/nuget-vendoring-prototype) was built after the design review. Building it and testing it against real `dotnet` changed several decisions. When anything below conflicts with this table, **this table wins**. The full list is in §17. - -| Design text | Prototype (authoritative) | Why | -|---|---|---| -| `.socket/vendor/nuget` is listed as an "anchor" fallback folder, so restore fails with NU1301 when it is missing (§6.3, G12) | **Removed.** The DBP block now holds a `SocketPatchNuGetImportCheck` target that fails restore with **SOCKETPATCH007** when `socket-patch.targets` was not imported | With the anchor, anyone could plant `//` next to the uuid dirs and NuGet would restore it under `--locked-mode` with no seed check. The security review reproduced this on SDK 8. SOCKETPATCH007 is proven by e2e for both locked and unlocked restore. | -| V′ carries a builder bit: `N = 2^30 + ((u32 >> 3) << 1) + builder` (§6.1) | `N = 2^30 + (u32(uuid[0..8]) >> 2)`, with **no builder bit** | contentHash is `base64(sha512(canonical zip of the seed file set))`. It does not depend on whether the bytes came from the service or a local rebuild, so one uuid gives one V′ and one hash. | -| Seed dirs named by uuid8 (§6.2) | Full canonical uuid: `.socket/vendor/nuget////` | Keeps `vendor_uuid_dir_rel`, the orphan sweep and the path parsers unchanged. Long Windows paths are still an open item (G8). | -| `--nuget-layout` flag on `GlobalArgs`, and a `nugetShared` ledger section (§5, §6.7) | Opt in with `SOCKET_PATCH_NUGET_LAYOUT=fallback`, or automatically once the ledger has a `nuget-fallback` entry. A purl the ledger holds as a legacy feed entry keeps the feed layout. Shared outputs are rendered from the per-uuid markers, using the ledger `fileInventory` when there is one. | Keeps the prototype contained in the core backend with a few CLI routing lines. It needs no new ledger schema. | -| Lock revert from per-edit records (§6.5, §7.4) | One `nuget_lock_file_v2` record per lock. Revert **unsplices only this entry's V′ values**, back to the recorded originals. | Seeds that share a lock can be reverted in any order, and edits made after vendoring are kept. | -| SOCKETPATCH003/004/006, per-project transitive pins, `--check`, pack range restore, VEX extractor | Not in the prototype. Transitive-only use refuses with `vendor_nuget_transitive_only` (CPM with transitive pinning is supported). | Scope (§15 was too large for one PR). | - -## 1. Status and summary - -**Status.** Proposed. This design ships as an opt-in layout, `--nuget-layout=fallback`, next to today's feed layout. Today's layout stays the default until the promotion criteria in §15 are met. Hosted mode is unchanged. packages.config projects stay on the legacy layout. A repo that has both packages.config and SDK projects using the same id@V is refused (§5). - -**Summary.** The patched package gets its own version, V′, that nothing else can produce. For a stable 3-part upstream version, V′ adds a 4th part derived from the patch uuid, for example `13.0.1` → `13.0.1.1340506222`. The package is committed already extracted, as a NuGet fallback package folder at `.socket/vendor/nuget////`. - -The CLI adds one generated block to the nearest `Directory.Build.props` (DBP) of every SDK project. The block has three parts: -- It appends `.socket/vendor/nuget/socket-patch.targets` to `CustomAfterDirectoryBuildTargets`. MSBuild imports that property after the whole `Directory.Build.targets` chain. -- It adds a restore-time `SocketPatchNuGetImportCheck` target. If the targets file was not imported, for example because `.socket/vendor/nuget` is missing, restore fails with SOCKETPATCH007. (§0: this replaces the original anchor fallback folder.) -- It adds one literal uuid comment per patch. - -The generated targets file does five things: -1. It adds each uuid8 directory to `RestoreAdditionalProjectFallbackFolders`. -2. It redirects the planned references to the floor range `[V′, )`, using evaluation-time `Update` and `Include` items. Direct references, CPM `PackageVersion`, and TFM-conditioned transitive pins are all handled. An exact `[V′]` is not used, because it spreads through ProjectReference (§16, S-B1). -3. At restore time, it checks that the files in the seed are exactly the recorded set and have the recorded hashes (SOCKETPATCH001/002). -4. At build time, it checks the files that were actually consumed: - - where they resolved from, and whether their content matches (SOCKETPATCH003); - - whether the project resolved the unpatched V (SOCKETPATCH005); - - whether a project where a redirect engaged resolved anything other than V′ (SOCKETPATCH006). -5. It writes the original version range back into packed nuspecs, checks the nuspec before and after pack, and deletes a nupkg that leaks V′ (SOCKETPATCH004). - -The CLI also edits, entry by entry, every lock whose graph contains a redirected project. It writes `.socket/vendor/nuget/.gitattributes` so that git stores the seed bytes exactly as written. - -**Why this shape:** -- The global packages folder (GPF) is never read or written for the patched package. Every other package keeps its normal GPF and caches. -- `nuget.config` is never edited in the fallback tier. -- Source mapping, user, CI and ancestor configs, `--source`, `NUGET_PACKAGES`, `--packages` and `locals --clear` do not affect the patched package. -- Revert is deterministic: remove the generated block, restore the recorded lock entries, delete the seed. No cache eviction is needed. - -**What the lock gives, and what it does not.** In the fallback tier the lock `contentHash` is compared only with the committed `.nupkg.metadata`, so it pins version identity only. Byte integrity comes from three checks: -- the restore-time set-and-hash check of the seed; -- the build-time check of consumed files; -- `vendor --check --online`, which rebuilds the expected seed from an anchor outside the repo (§7.3). - -**Enterprise `signatureValidationMode=require`.** A fallback folder is never signature-verified. These repos need the feed tier (§10). That tier is out of prototype scope and waits on depscan's CA-issued signing. - -## 2. Background: verified NuGet facts - -The research reports cited below, for example `lock-cache §c`, `sources §b` and `adv-env`, are committed in [`nuget-vendoring-research/`](nuget-vendoring-research/). They are the raw notes of the parallel research agents and the adversarial reviewers. `` paths in them refer to the throwaway sandbox the experiments ran in. - -All runs used .NET SDK 8.0.131 (NuGet 6.8.2) on Linux. Labels: -- **VERIFIED**: run in the original research; the report is cited. -- **VERIFIED-D / -C**: run by the candidate authors. -- **VERIFIED-ADV**: run by the adversarial reviewers: `adv-shapes eN`, `adv-env`, `adv-integrity xN`, `adv-lifecycle VN`. -- **DOCS**: documentation only. -- **REASONED**: inferred from code or from verified facts; not run. -- **UNVERIFIED**: a proposal waiting on a gating experiment (§14). - -### 2.1 Why the same id+version cannot be made safe -| Fact | Status | -|---|---| -| The GPF is keyed by id/version only. The first writer wins, and the entry is never refreshed, even with `--force --no-cache --force-evaluate`. | VERIFIED lock-cache §c, sources §a | -| A failed `--locked-mode` restore (NU1403) still extracts the wrong copy into the GPF. | VERIFIED lock-cache §b | -| Lock `contentHash` is compared only with `.nupkg.metadata`. A tampered dll passes locked restore. | VERIFIED lock-cache §b/§c; VERIFIED-ADV x1 (a seed) | -| Patched bytes leak to other lockless projects on the same GPF, and the reverse happens too. | VERIFIED lock-cache §c, shapes §1A | -| For the **same** id+version, the GPF beats a fallback folder. This is also true for V′: a GPF copy of V′ wins over the seed. | VERIFIED lock-cache §e; VERIFIED-ADV x2, adv-env M1 | -| A fallback folder is used in place and never copied into the GPF. The minimum content is `.nupkg.metadata`, the nuspec and `lib/`. NuGet enumerates the whole directory, so extra `build/` files are imported. | VERIFIED lock-cache §e; VERIFIED-D V-D1/2; VERIFIED-ADV x1 | -| A missing folder in `RestoreAdditionalProjectFallbackFolders` gives NU1301 in every project that imports it. | VERIFIED-ADV V2 | -| Restore ignores missing imports. It rewrites locks to upstream, and only `build` fails with MSB4019. | VERIFIED-ADV V3 | - -### 2.2 Source routing is fragile -| Fact | Status | -|---|---| -| Source mapping is exclusive and matches by id, not version. Mapping an id to a local feed breaks the id's other versions (NU1102). | VERIFIED sources §b | -| When two sources hold the same id+version, the first to respond wins, so the result is nondeterministic. | VERIFIED sources §d | -| A user-level mapping hides an unmapped repo source. A nearer file replaces a farther file's patterns for the same key. `` drops farther levels. | VERIFIED sources §b/§c | -| Config probing covers 3 spellings in every ancestor, then user, `config/*.config` and machine files. | VERIFIED sources §c | - -### 2.3 Version identity -| Fact | Status | -|---|---| -| `X.Y.Z+meta` collides with X.Y.Z. `X.Y.Z-socket.N` sorts below X.Y.Z, which gives NU1605 and a false NU1903. | VERIFIED lock-cache §g, shapes §1B | -| A 4-part `X.Y.Z.N` gets its own GPF directory and sorts above X.Y.Z. It works as a direct reference and as a CentralTransitive pin. | VERIFIED lock-cache §g, shapes §1B | -| NuGetAudit still flags V′ whenever the advisory's vulnerable range includes V′. Example: `12.0.1.N` against the `< 13.0.1` advisory. "No false NU1903" holds only when the fix is V's next release. | VERIFIED-ADV e1, V1 (this corrects revision 1) | -| An exact `[V′]` spreads through ProjectReference. It causes NU1107 against a sibling's `>= 13.0.3`, NU1107 across two patched versions of one id, and NU1608 in consumers. | VERIFIED-ADV e2 | -| With `[V′, )` the declaring project resolves V′, AppA/AppC resolve 13.0.3 as before, and AppB resolves 13.0.1.N. No NU1107 or NU1608. | VERIFIED-ADV e2 | -| When V′ is unreachable (an external consumer), `[V′, )` silently resolves the next higher version (NU1603). | VERIFIED-ADV e8 | -| Floating ranges never select a 4th-part version. | VERIFIED shapes §7 | -| A unique version leaks into packed nuspecs. | VERIFIED shapes §1B | -| `Version="13.0.1.0"` means the same as 13.0.1 to NuGet but does not match the literal condition. | VERIFIED-ADV e9 | - -### 2.4 MSBuild and injection -| Fact | Status | -|---|---| -| Only the nearest DBP/DBT is imported. Chaining with `GetPathOfFileAbove` works. | VERIFIED shapes §4 | -| With chained DBTs, an import at the end of a nested DBT runs too early when it has a once-guard, so the redirect misses items declared later. | VERIFIED-ADV e7 | -| `CustomAfterDirectoryBuildTargets`, set in DBP, is imported after the whole DBT chain (`Microsoft.Common.targets:55`), without the `ImportDirectoryBuildTargets` condition. | VERIFIED-ADV e7 (SDK 8 only) | -| Our file, imported after DBT, comes after package `build/*.targets`. An unconditional property assignment there beats env vars and package props; only a global `-p:` beats it. | VERIFIED-ADV x1 | -| `@(Item->WithMetadataValue(...))` conditions on evaluation-time ItemGroups work for PackageReference and PackageVersion Update. GlobalPackageReference and case-variant ids are covered. | VERIFIED shapes §2; VERIFIED-D e1/e7; VERIFIED-ADV (shapes) | -| A PrivateAssets=all pin becomes a Direct lock entry and does not leak into pack. Without `Publish="true"` the dll is missing from publish output. | VERIFIED shapes §5; VERIFIED-D V-D11 | -| A pin without a `$(TargetFramework)` condition adds a new Direct dependency to every TFM. | VERIFIED-ADV e3 | -| The `AfterTargets=ResolvePackageAssets` guard runs in design-time builds. | VERIFIED-ADV (adv-env M2) | -| Evaluation-time redirects work under static-graph restore (sln, and CPM with pinning on). SOCKETPATCH001 at `BeforeTargets=CollectPackageReferences` fires in normal and static-graph restore. | VERIFIED-D V-D3b; VERIFIED-ADV (shapes) | -| The guard as written runs cleanly: it parses, batches, and preserves `GetFileHash` metadata. Cost is 52 ms per project for an 8.7 MB seed. | VERIFIED-ADV (shapes, env) | - -### 2.5 Integrity, signing and git -| Fact | Status | -|---|---| -| For an unsigned nupkg, contentHash = base64(sha512(file)). For a signed nupkg it is computed with `.signature.p7s` removed. Signing never changes contentHash. | VERIFIED lock-cache §a, signing §e | -| depscan's SRI with `sha512-` removed equals the unsigned contentHash. | VERIFIED depscan §1 | -| Keeping the upstream signature on changed bytes gives NU3008. An unsigned package under `require` gives NU3004. Package and fallback folders are never verified. | VERIFIED signing §a/§b; VERIFIED-D V-D9 | -| A self-signed author cert plus `` passes `require`. `` trust has no id scope. | VERIFIED signing §b/§c; DOCS | -| `* text=auto`, `core.autocrlf=true` and `eol` rules rewrite seed text members. The author's tree stays clean, and every clone gets different bytes. | VERIFIED-ADV adv-env B1, x4/x5, V4 | -| A nested `.gitattributes` with `* -text -diff -merge -filter` gives byte-identical clones under hostile root rules. | VERIFIED-ADV adv-env c2, V4 | -| Seed files added outside the nuspec are imported and can disable a guard whose assignment is conditional. | VERIFIED-ADV x1 | - -## 3. Candidates considered - -| Key | Summary | Judge mean (/100) | -|---|---|---| -| A (feed hardened) | Same-version local feed, chain-aware mapping, pins in every lock, gitignored per-generation `RestorePackagesPath` | 59.6 | -| B (unique version via feed) | `X.Y.Z.(D+1)-socket.p.` in a local feed, with per-project redirects | 70.5 | -| C (repo-local seed) | Same id+version seeded into a committed repo-wide `RestorePackagesPath` | 70.2 | -| D (unique-version fallback seed) | 4th-part V′ in a committed fallback folder; no config edits | **76.3** (chosen by 2 of 3 judges) | - -Mean judge scores per criterion (1–10; the total is out of 100, with correctness, GPF safety and integrity weighted double). Each judge scored through a different lens: shapes and environments, integrity and supply chain, and operability. - -| Candidate | correctness | integrity | gpf safety | diff size | revert | ci friction | impl cost | server side | total | -|---|---|---|---|---|---|---|---|---|---| -| A-feed-hardened | 5.7 | 7.0 | 7.7 | 5.7 | 6.3 | 3.7 | 3.7 | 5.7 | 59.6 | -| B-unique-version | 6.3 | 7.7 | 9.7 | 5.7 | 8.0 | 5.3 | 2.7 | 8.3 | 70.5 | -| C-repo-local-seed | 7.7 | 7.3 | 9.3 | 4.3 | 8.0 | 4.0 | 6.3 | 5.7 | 70.2 | -| D-wildcard | 7.7 | 7.3 | 9.7 | 5.7 | 8.7 | 8.3 | 4.7 | 7.7 | 76.3 | - -## 4. Decision - -**D is the base.** The grafts from the other candidates: -- **From C:** the resolved-root and consumed-file hash guard, now content-aware; `.gitignore` negations checked with `git check-ignore`; eviction of GPF entries leaked by the legacy layout, identified through `.nupkg.metadata` `source`. -- **From B:** an invertible V′ derivation shared with depscan; the declared-version guard; refusal when a dependency constraint excludes V′; server-recorded upstream hashes; a sandboxed relock; the pack-roots policy; NuGetAuditSuppress. -- **From A:** version-precise pins in every affected lock; config-chain discovery, used for signature policy only; the WIRING_FILES and sweep fix; the fix for the id-only hosted lock match at `redirect/mod.rs:5431`. - -**C was rejected** because a repo-wide `RestorePackagesPath` moves every package into the repo. That throws away the CI and developer GPF caches and breaks Docker layers and scripts, which is an operational regression for every repo. - -**Structural changes after adversarial review:** -1. The floor range `[V′, )` replaces `[V′]`. SOCKETPATCH006 is added, and lock edits reach every consumer of a redirected project. -2. The injection point moves from a DBT Import line to a DBP `CustomAfterDirectoryBuildTargets` block. -3. A generated `.gitattributes` is added, and `--check` compares against committed blobs. -4. A restore-time set-equality check of the seed is added. The guard property is assigned unconditionally. Exemptions come from a CLI-managed allowlist. -5. The foreign-root check depends on content, and hash keys are `//`. -6. Shared outputs are regenerated by a CLI finalize hook (`sync_shared`) that runs after every ledger mutation. Removing the block needs no records. -7. Patch updates, revert ordering, migration ordering and v4 compatibility are specified (§7.4–§7.7). -8. Directories are named by uuid8, and the long-path check uses absolute paths. - -## 5. Tiers and layout selection - -| Tier | When | Mechanism | -|---|---|---| -| **fallback** | SDK-style PackageReference projects with no visible require policy | Committed extracted seed. Prototype scope. | -| **feed** | A require policy is visible, the depscan org policy says require, or `--nuget-tier=feed` | Signed V′ nupkg in a per-uuid flat feed. Builder 0 (service bytes) only. Post-prototype, blocked on G6 and depscan #8 (§10). | -| **legacy** | packages.config-only repos, `--nuget-layout=feed`, and existing legacy entries | Today's `nuget_feed.rs`, unchanged. | - -**Selection rules:** -- The layout is selected by `--nuget-layout ` on `GlobalArgs`, so it applies to vendor, scan, get and repair. The environment variable is `SOCKET_NUGET_LAYOUT`. The default is `feed` until promotion. -- **Inference:** if any `nuget-fallback` entry exists, or the top-level optional `state.nugetLayout == "fallback"`, new NuGet entries use fallback whatever the flag says. The first fallback vendor sets `nugetLayout`. -- **Hybrid router:** an entry whose `flavor` is `nuget-fallback`, or that carries `nuget_lock_entry_v2` records, always routes to the fallback backend. This covers entries that an older binary relabelled (§11.3). -- **Refusals:** - - `vendor_nuget_tier_mixed`: more than one tier per repo. - - `vendor_nuget_mixed_project_styles`: packages.config and SDK projects resolve the same id@V. A dual-wiring entry is open question Q5. - -## 6. Mechanism - -### 6.1 Deriving V′ -The function is pure and must be identical in `vendor/nuget_version.rs` and in depscan `lib/src/nuget/socket-version.ts`, with shared golden vectors. Its inputs are the normalized upstream V, the uuid, and the builder (service = 0, local = 1). - -| Upstream V | V′ | Status | -|---|---|---| -| Stable, ≤ 3 parts or zero 4th part | `V.N`, where `N = 2^30 + ((u32(uuid[0..8]) >> 3) << 1) + builder`, in [2^30, 2^31−1] | Form VERIFIED-D (e1/e7) | -| 4-part with D > 0 | `A.B.C.(D+1)-socket.p.` | Refused (`vendor_nuget_version_unsuffixable`) until G5 | -| Prerelease | `X.Y.Z-pre.socket.p.` | Refused until G5 | - -- **Example:** uuid `3f9a01bc-…` gives `13.0.1.1340506222` for a service build, and `…223` for a local build. -- **Collision refusals:** - - `vendor_nuget_version_collision`: two entries for the same id@V derive the same V′. - - `vendor_nuget_version_gap`: a published version of the id lies in (V, V′]. For example, an upstream 4-part `13.0.1.5` would change floor-range resolution. The server checks nuget.org and the org's configured upstreams (adv-env m7). The CLI repeats the check against the flatcontainer index when it is online. -- **One V′, one byte sequence:** service artifacts are write-once per uuid. Builder 1 is not a single byte producer (adv-integrity M4), but in the fallback tier V′ bytes exist only in the committed seed, so the only cost is lock churn. The feed tier accepts builder 0 only. -- The hot path accepts either builder for an existing uuid. The builder changes only with `--nuget-rebuild-service` (Q4). - -### 6.2 On-disk layout (fallback tier) -``` -Directory.Build.props EDITED (socket-patch block) or CREATED -src/Directory.Build.props EDITED where it is the nearest DBP of an SDK project -src/Lib/packages.lock.json EDITED (entries for id@V and Project ranges only) -src/AppA/packages.lock.json EDITED (Project range only: consumer of a redirected project) -.socket/vendor/state.json flavor "nuget-fallback", nugetLayout, nugetShared -.socket/vendor/nuget/ - socket-patch.targets GENERATED by sync_shared (LF, -text) - .gitignore GENERATED (negations) - .gitattributes GENERATED - 3f9a01bc/ fallback root (uuid8; full uuid in marker + state) - socket-patch.vendor.json - newtonsoft.json/13.0.1.1340506222/ - .nupkg.metadata {"version":2,"contentHash":"","source":null} - newtonsoft.json.nuspec - lib/netstandard2.0/Newtonsoft.Json.dll (patched) - … -``` - -**`.gitattributes`:** -``` -* -text -diff -merge -filter -/socket-patch.targets -text diff -/.gitignore -text diff -/.gitattributes -text diff -``` - -**`.gitignore`:** -``` -!/3f9a01bc/ -!/3f9a01bc/** -!/socket-patch.targets -!/.gitattributes -``` - -**Post-write checks.** After writing, the CLI runs: -- `git check-ignore` on the seed files, refusing with `vendor_artifact_gitignored`; -- `git check-attr text eol filter` on the seed files, refusing with `vendor_artifact_git_transformed`, for example when a root LFS rule survives. - -**Seed extraction.** The seed is extracted from the V′ nupkg following NuGet's own rules: -- entry names are percent-decoded, **then** validated with `is_safe_relative_subpath`, `is_plain_archive_name` and `names_are_unambiguous`, compared case-folded; -- names containing any of `$ @ % ; ' = ( )` are refused (`vendor_nuget_unsafe_member`); -- OPC parts and `.signature.p7s` are dropped; -- the nuspec is renamed to `.nuspec`; -- no `.nupkg` or `.sha512` is written; -- the existing zip-bomb caps (`MAX_ENTRIES`, per-entry and total limits) are reused. - -**Size and path limits:** -- `vendor_nuget_seed_too_large` if any file is over 50 MB or the seed is over 200 MB (configurable). -- `vendor_nuget_long_path` warns when the absolute path, under a pessimistic 60-character CI prefix or the real root, exceeds 240 characters. Above 250 characters the CLI refuses unless `--allow-long-paths` is given. - -### 6.3 Directory.Build.props block -```xml - - - - $(CustomAfterDirectoryBuildTargets);$(MSBuildThisFileDirectory).socket/vendor/nuget/socket-patch.targets - $(RestoreAdditionalProjectFallbackFolders);$(MSBuildThisFileDirectory).socket/vendor/nuget - - -``` - -**Placement.** The block goes in the nearest DBP of **every** SDK project in the same git worktree, including projects that do not use the patched package. That lets SOCKETPATCH005 and 006 cover projects added later. Submodules, template content (`PackageType=Template`) and dot-directories are skipped, with warning `vendor_nuget_import_skipped`. Nested files use a relative `../` path. If the root has no DBP, the CLI creates `` containing the block and nothing else. - -**What the block does:** -- **Import ordering.** The targets are imported after the entire DBT chain, which fixes the nested-chain misfire (VERIFIED-ADV e7, SDK 8). The `Contains` guard dedupes chained DBPs. Whether the property exists on SDK 6 and 7 is G10. -- **Restore fail-closed.** Superseded (§0). The anchor folder let anyone plant packages. The prototype's `SocketPatchNuGetImportCheck` target fails restore with SOCKETPATCH007 instead. VERIFIED in the e2e. -- **v4 compatibility.** The literal uuid comments let v4 drift-keep and VEX liveness see the uuid (§11.3). - -**Refusals:** -- `vendor_nuget_dbp_disabled`: a project sets `ImportDirectoryBuildProps=false`. -- `vendor_nuget_non_sdk_project`: a non-SDK project uses PackageReference, because the guard would never run there (adv-shapes M5). - -### 6.4 `socket-patch.targets` (generated; illustrative, deterministic, sorted) -The example repo: -- Lib has a direct 13.0.1 reference. -- AppA references Lib and Lib3 (13.0.3). -- Tool gets 12.0.1 through Bson, for netstandard2.0 only. -- Web uses CPM. - -```xml - - - - - true - true - $([MSBuild]::NormalizeDirectory('$(MSBuildThisFileDirectory)')) - $([MSBuild]::NormalizeDirectory('$(MSBuildThisFileDirectory)', '..', '..', '..')) - $([MSBuild]::MakeRelative('$(SocketPatchRepoRoot)', '$(MSBuildProjectFullPath)').Replace('\', '/')) - <_SpV_3f9a01bc>13.0.1.1340506222 - <_SpV_7c21d0e4>12.0.1.1994350720 - $(RestoreAdditionalProjectFallbackFolders);$(SocketPatchNuGetDir)3f9a01bc;$(SocketPatchNuGetDir)7c21d0e4 - <_SpPatched>;newtonsoft.json/$(_SpV_3f9a01bc);newtonsoft.json/$(_SpV_7c21d0e4); - <_SpUpstream>;newtonsoft.json/13.0.1;newtonsoft.json/12.0.1; - <_SpAllowUnpatched>;src/Legacy/Legacy.csproj; - <_SpHashes>;newtonsoft.json/13.0.1.1340506222/lib/netstandard2.0/newtonsoft.json.dll=4F33…BD;…; - - - - - - - - - - - - - - - - - - - - - - - - - - - - <_SpOnDisk Include="$(SocketPatchNuGetDir)3f9a01bc/**;$(SocketPatchNuGetDir)7c21d0e4/**" Exclude="$(SocketPatchNuGetDir)*/socket-patch.vendor.json" /> - <_SpExtra Include="@(_SpOnDisk)" Exclude="@(SocketPatchSeedFile)" /> - <_SpMissing Include="@(SocketPatchSeedFile)" Condition="!Exists('%(FullPath)')" /> - - - - - <_SpSeedChecked>true - - - - - - <_SpCand Include="@(RuntimeCopyLocalItems);@(ResolvedCompileFileDefinitions);@(RuntimeTargetsCopyLocalItems);@(NativeCopyLocalItems);@(ResourceCopyLocalItems);@(Analyzer)" - SpKey=";$([System.String]::Copy('%(NuGetPackageId)/%(NuGetPackageVersion)').ToLowerInvariant());" /> - <_SpPatched Include="@(_SpCand)" Condition="$(_SpPatched.Contains('%(SpKey)'))" /> - <_SpUnpatched Include="@(_SpCand)" Condition="$(_SpUpstream.Contains('%(SpKey)'))" /> - <_SpDrift Include="@(_SpCand)" Condition="'@(SocketPatchRedirect)' != '' and '%(NuGetPackageId)' != '' and $([System.String]::Copy('@(SocketPatchRedirect)').ToLowerInvariant().Contains('$([System.String]::Copy('%(NuGetPackageId)').ToLowerInvariant())/')) and !$(_SpPatched.Contains('%(SpKey)'))" /> - - - - - - <_SpBad Include="@(_SpHashed)" Condition="!$(_SpHashes.Contains(';%(SpKeyPath)=%(FileHash);'))" /> - - - - - -``` - -**Notes on the file:** -- **Content-aware foreign root.** `SpKeyPath` is `//`, computed from the path relative to the package root it resolved in. The mechanics are G15. A byte-identical copy in the GPF passes. A different copy fails SOCKETPATCH003. The error message no longer tells the user to delete the folder. -- **Package presence.** Presence is decided from `@(_SpCand)`, which now includes `@(Analyzer)`. For packages with no lib, ref or analyzer assets, the guard also reads the `libraries` keys of `project.assets.json` (G1). -- **Guard escape hatch.** `SocketPatchNuGetGuard` is assigned unconditionally, so the only way to turn it off is a global `-p:SocketPatchNuGetGuard=false`. `vendor --check` flags `*.rsp` files that mention `SocketPatch*`. -- **SOCKETPATCH005 exemptions.** Projects are exempted only through `_SpAllowUnpatched`, which is rendered from `state.nuget.allowUnpatched` (`socket-patch vendor --nuget-allow-unpatched `). There is no free-form property any more. -- **Versions behind properties.** Versions sit in `_SpV_*` properties, so regex updaters see no literals. If a bot edits them anyway, SOCKETPATCH006 fires, and `--check` compares the render sha. -- **Split CPM.** When one central PackageVersion resolves differently across projects, the CLI emits the per-project form `('$(SocketPatchProject)'=='a' or …)` (VERIFIED-D e7). A CPM transitive-only project gets a Version-less `Include` pin plus `Publish="true"`. A `VersionOverride` equal to V gets `VersionOverride="[V′, )"`. VersionOverrides to other versions are left alone. -- **TFM conditions.** Pin TFM conditions use the alias taken from assets `project.frameworks`. A multi-TFM pin with no assets file, or with a custom alias, is refused (`vendor_nuget_tfm_alias_unknown`). - -### 6.5 Lock edits -**Which lock.** For each project, in order: -1. a static `NuGetLockFilePath` (a dynamic value is refused with `vendor_nuget_lockpath_dynamic`); -2. `packages..lock.json`; -3. `packages.lock.json`. - -**Edits.** Splices are byte-preserving and TFM/RID-scoped. The exact `[V′, )` text is G11; the goldens are re-captured from `--force-evaluate`. - -| Project role | Before | After | -|---|---|---| -| Direct / CPM direct | `Direct`, `requested "[13.0.1, )"`, `resolved 13.0.1` | `Direct`, `requested "[V′, )"`, `resolved V′`, `contentHash ` | -| CPM uniform, pinning on (CentralTransitive) | `CentralTransitive`, `requested "[13.0.1, )"` | stays `CentralTransitive`; `requested "[V′, )"` plus new resolved and hash (VERIFIED-ADV e5 corrects revision 1) | -| Transitive pin | `Transitive` | `Direct` with `requested` inserted. Written in NuGet's canonical order: Direct entries first (VERIFIED-ADV e3). | -| Auto-follow consumer that resolved V | `Transitive 13.0.1` | `Transitive V′` plus hash | -| Consumer that resolved R > V (AppA/AppC) | unchanged | unchanged. Its resolution is R because R > V′ is guaranteed by the gap check. | -| `Project` entry listing a redirected project | `"[13.0.1, )"` | `"[V′, )"`, in **every** lock whose graph contains that project | - -**Records.** -- One record per edit: `nuget_lock_entry_v2` (key `#[/]#`) or `nuget_lock_project_range`. -- Records are stored EOL-neutral, together with the observed EOL. -- Live-text comparisons normalize CRLF to LF, and splices use the live file's EOL. -- Relock comparison is semantic (parsed JSON), not textual. - -### 6.6 Pack -- **Range restore** (`AfterTargets=_GetAbsoluteOutputPathsForPack`, VERIFIED-D V-D6 and VERIFIED-ADV e5): `"[V′, )"` is replaced with the **recorded original literal range**, for example `[13.0.1]` stays exact. -- **Pre-check**, `BeforeTargets=GenerateNuspec`: fail SOCKETPATCH004 if the rewritten assets still contain any V′. -- **Post-check**, `AfterTargets=GenerateNuspec`: read exactly `$(NuspecOutputAbsolutePath)$(PackageId).$(PackageVersion).nuspec`. This avoids MSB4184 when several nuspecs are present (VERIFIED-ADV e5). On failure, `` runs before the error, because the nupkg was already written (VERIFIED-ADV e5). -- Both checks are G2. If G2 fails on any supported SDK, packable projects with a direct patched reference are refused (`vendor_nuget_packable_direct`). Opt-in: `--nuget-pack-policy=roots`. - -### 6.7 State -```json -{"ecosystem":"nuget","flavor":"nuget-fallback","basePurl":"pkg:nuget/Newtonsoft.Json@13.0.1","uuid":"3f9a01bc-…", - "artifact":{"path":".socket/vendor/nuget/3f9a01bc/newtonsoft.json/13.0.1.1340506222","sha256":"", - "fileInventory":{"lib/netstandard2.0/Newtonsoft.Json.dll":"4f33…","…":"…"}}, - "nuget":{"tier":"fallback","wired":true,"upstreamVersion":"13.0.1","patchedVersion":"13.0.1.1340506222", - "builder":"local","contentHash":"FRVi…","upstreamSha512":"…","upstreamContentHash":"…","packPolicy":"restore-ranges", - "literals":["13.0.1","13.0.1.0"],"allowUnpatched":[], - "projects":[{"path":"src/Lib/Lib.csproj","role":"direct","declared":"13.0.1","tfms":["net8.0"]}, - {"path":"src/AppA/AppA.csproj","role":"range-consumer","tfms":["net8.0"]}]}, - "wiring":[ - {"file":"src/Lib/packages.lock.json","kind":"nuget_lock_entry_v2","key":"…#net8.0#Newtonsoft.Json","original":"…","new":"…"}, - {"file":"Directory.Build.props","kind":"nuget_uuid_anchor","action":"Referenced"}]} -``` -Top-level additions to `VendorState`, all additive and optional: -- `nugetLayout`; -- `nugetShared`: `{renderSha256, props:[{file, created, original}]}`. - -**Rules:** -- The DBP block is owned by the state, not by any entry. `nuget_uuid_anchor` is a reference only: v5 never reverts from it, and it exists so v4 sees the file (§11.3). -- `nuget.projects` is the authoritative closure (§7.2). -- `wired=false` marks Preserved or Kept entries. `sync_shared` never renders them. -- `fileInventory` intactness replaces the existence-only `ledger_covers` check for directory artifacts. - -## 7. Algorithms - -### 7.1 Apply (`vendor_nuget_fallback`) -1. **Prelude** (`fallback_prelude`, shared with `service_preflight`). It refuses on: - - unsafe coordinates; - - `version_unsuffixable`, `version_gap`, `version_collision`; - - signature policy: config chain for every project directory, plus `DOTNET_NUGET_SIGNATURE_VERIFICATION`; - - `mixed_project_styles`, `dbp_disabled`, `non_sdk_project`; - - `external_consumer`: a project outside the root references a redirected project, or an `.sln`/`.slnf` above the root lists one; - - `exact_dependency`: a dependency constraint excludes V′; - - `version_literal_unknown`: property-expanded versions on an SDK without `-getItem` (< 8), which are refused; - - `sdk_unavailable`: the SDK that `global.json` pins is not installed; - - `implicit_reference`: `IsImplicitlyDefined`, for example FSharp.Core; - - `tool_only`: tool packages cannot be patched this way, and the crawler must not claim that they are covered; - - `tier_mixed`, `layout_mixed`. - - Entries that share this entry's ledger key or basePurl are excluded from the duplicate and collision checks. -2. **Closure plan** (`plan_closure`): - - Enumerate `*.*proj` plus the projects listed in the sln. Skip dot-directories, `bin`, `obj`, `node_modules` and configured package folders. - - Read assets, or else the lock, or else csproj and CPM text. - - Count a `resolved` that decodes (`parse_socket_nuget_version`) to (id, V) as V. - - Roles: `direct`, `cpm-uniform`, `cpm-split`, `auto-follow`, `pin`, and `range-consumer`. A range-consumer is any project whose graph reaches a redirected project; ProjectReferences are walked in both directions. - - Projects that are already planned and have no assets are not refused. `vendor_nuget_unrestored` applies only to **new** projects with neither a lock nor assets. -3. **Materialise the V′ nupkg:** - - from the service `nupkg-socket-version` artifact (builder 0), or - - by running `reversion_nupkg` on the SRI-verified same-version service nupkg or on `local_rebuild` output (builder 1). - - The upstream is verified by its repository signature, or by sha512 against depscan `upstreamSha512`. Every patched member is checked against its afterHash. -4. **Stage everything in memory:** the seed tree, all lock splices, and the new DBP blocks. -5. **Write, with snapshots:** - - Write the seed atomically (temp directory, then rename). Reuse it if it already matches `fileInventory`. - - Snapshot the bytes of every file about to be touched, then write the locks and DBPs, each by temp file and rename. -6. Optional `--nuget-relock`: a sandboxed `--force-evaluate` run with a throwaway `NUGET_PACKAGES`, then a semantic diff against the planned key set. -7. **Unwind** on any failure in steps 5–6: restore every snapshot, and delete the seed only if this run created it. -8. Return `VendorOutcome::Done`. The CLI then persists the entry, sweeps stale artifacts, and calls **`sync_shared`**. - -### 7.2 `sync_shared(cwd, &VendorState)`, the CLI finalize hook -It is called after every ledger mutation: `run_vendor` (after persist and sweep), revert, rollback, remove, gc, repair, and scan/get in vendored mode. It runs: -- in memory during `--dry-run`; -- idempotently; on failure it reports `vendor_nuget_shared_sync_failed` and exits non-zero. - -What it does: -1. It selects entries that are `nuget-fallback`, `wired`, and whose seed directory is present. For an entry that is wired but has a missing seed, it warns and does not render it. -2. If the selection is non-empty: - - it renders `socket-patch.targets`, `.gitignore` and `.gitattributes`, and writes the DBP blocks into every nearest DBP; - - it refuses without `--force` when the on-disk targets differ from `nugetShared.renderSha256` (`vendor_nuget_targets_edited`). -3. If the selection is empty: - - it removes the block from every discovered DBP, plus every DBP listed in `nugetShared.props`, without needing any per-entry records; - - it deletes a DBP whose text equals the created text; otherwise it restores `original` when the rest of the file is unchanged; - - it deletes the targets file only after every block is gone. If any excision drifts, it writes a stub `` targets file instead; - - it deletes `.gitignore` and `.gitattributes` last. - -### 7.3 Hot path, `--check`, `--check --online` -**In sync**, which returns `AlreadyPatched`, requires all of: -- the seed file set equals `fileInventory`, with no extra, symlinked or non-regular files, and the hashes match; -- `.nupkg.metadata` equals the recorded contentHash; -- the shared outputs are byte-equal to the render (they are `-text`, so this is safe); -- every lock record's live text equals `new`, compared EOL-neutral; -- a re-plan from csproj, CPM and locks, with V′ counted as V, matches `nuget.projects`. - -A changed closure is re-planned and re-keyed, and warns `vendor_nuget_closure_changed`. - -**`--check`** does everything above, plus: -- it compares seed hashes against the **committed** blobs (`git cat-file HEAD:`) and checks `git ls-files --eol`, reporting `vendor_nuget_eol_normalized`; -- it evaluates every discovered project with `dotnet msbuild -getProperty:SocketPatchNuGetTargetsImported` (batched). Any project that resolves the id at V without importing the targets fails (`vendor_nuget_project_uncovered`); -- it probes the signature policy again; -- it flags repo trustedSigners that are not in state, and `.rsp` overrides; -- it reports untracked seeds, stale keys, unused entries and orphaned pins. - -It works before any restore, because it relies on the persisted closure. - -**`--check --online`** also rebuilds the expected tree from an anchor outside the repo and diffs it byte for byte. The anchor is either the service artifact (SRI) or upstream plus afterHashes. This is the recommended required CI step. - -### 7.4 Revert -Steps, in order: -1. **Lock records.** - - Live text equal to `new`: splice `original` back. - - Live text equal to `original`: the record is done. - - Otherwise it is drift. Drift is repaired **only** from depscan `upstreamContentHash`, or from a freshly downloaded nuget.org nupkg whose repository signature was checked. It is never repaired from the GPF (adv-integrity M5). -2. **keep** = any drifted record whose live text still contains V′. If keep is set, the entry becomes `wired=true`, `kept_artifact`, and the process stops here. -3. The CLI drops the entry, or marks it `wired=false` for Preserved, then saves state and runs `sync_shared`. That regenerates the targets or removes the blocks, deleting the targets only after the blocks are gone. -4. It deletes the seed and prunes empty levels. It first runs `refuse_symlinked`/`first_symlink` on the seed and all its ancestors. -5. No GPF eviction is needed (VERIFIED-D V-D12). - -### 7.5 Patch update (a new uuid for the same purl) -- The planner treats the old V′a as V (step 2). Lock edits V′a → V′b record `original: None`, so `carry_forward_wiring` fills in A's true upstream original. The key has no uuid in it. -- `carry_forward_wiring` merges import state across uuids implicitly, because that state now lives in the state-level `nugetShared`. -- The old entry is excluded from the prelude checks. The CLI replaces the entry, sweeps A's seed, and then runs `sync_shared`, which renders only B. -- Docker leg: vendor A, update to B, locked restore, revert, then `git diff --exit-code`. - -### 7.6 Migration from the legacy layout (`--migrate-nuget`) -1. Run `fallback_prelude` and `plan_closure` first. A refusal leaves legacy intact. -2. Materialise V′ by running `reversion_nupkg` on the **committed legacy `.nupkg`** (builder 1), and verify the afterHashes. Local rebuild is not used, because the GPF holds patched bytes. -3. As one unwindable unit: run the legacy revert (config, catch-all when the live text equals the legacy `new`, root lock), then apply fallback. -4. Opt-in `--nuget-evict-legacy-cache`: delete `//` GPF entries whose `.nupkg.metadata` `source` is a `.socket/vendor/nuget/` path, and print the command for CI caches. - -### 7.7 Pristine source on clean machines -When the GPF never holds upstream V, a rung fetches `https://api.nuget.org/v3-flatcontainer///..nupkg`. It verifies the result fail-closed against the upstream contentHash recorded in the ledger (the `original` of any `nuget_lock_entry_v2`), using the signed-content hash. Repair, patch update and `--offline` use this rung. - -For fallback entries, `vend_installed!` no longer `debug_assert`s `Installed`, and the hot path never reads `installed_dir`. - -### 7.8 Crawler, VEX, in-use -- **Crawler:** `nuget_crawler.rs` skips `.socket/vendor/nuget/**` packageFolders and maps V′ to (upstream purl, uuid). -- **VEX:** the fallback extractor parses `socket-patch.targets` (literal uuid comments and `_SpV_*`) and the discovered locks (V′ decoded). The nuget probe files gain the targets file, the DBPs and the locks. -- **In use:** an entry is in use when a lock or assets file resolves V′ for a reason other than our own pin. A pin with no remaining parent edge gives `vendor_nuget_pin_orphaned` and is dropped on the next `vendor`. - -## 8. Supported shapes (fallback tier) - -| Shape | Status | Evidence / notes | -|---|---|---| -| SDK sln, per-project locks, `--locked-mode`, warm or cold GPF | Supported | VERIFIED-D V-D3/V-D10, VERIFIED-ADV (env). Goldens for the `[V′, )` form: G11. | -| Patched library consumed next to a higher sibling (AppA/AppC) | Supported | `[V′, )` plus Project-range edits in every consumer lock (VERIFIED-ADV e2) | -| Multiple patched versions of one id reached by one project | Supported | Resolves the higher V′ (VERIFIED-ADV e2) | -| CPM, pinning off/on, VersionOverride | Supported | VERIFIED-D V-D7; static graph with pinning on VERIFIED-ADV | -| Transitive-only, multi-TFM | Supported | TFM-conditioned pin (VERIFIED-ADV e3 shows the need; the fix is G11) | -| Nested and chained DBT/DBP | Supported | `CustomAfterDirectoryBuildTargets` (VERIFIED-ADV e7 on SDK 8; SDK 6/7 is G10) | -| No lockfile | Supported, warning `vendor_nuget_no_lockfile` | 001/002/003/005/006 | -| Spelling variants `13.0.1.0`, `[13.0.1]` | Supported | One condition per recorded spelling. A new spelling in a new project gives loud 005. | -| `*.proj` NoTargets/Traversal, `.fsproj`, `.sqlproj` | Supported if SDK-style | Enumerated through `*.*proj` plus the sln | -| Any source mapping, ``, `--source`, `NUGET_PACKAGES`, `--packages`, `locals --clear` | Supported | VERIFIED-D V-D2/4/5b/9 | -| Byte-identical V′ in a shared GPF | Supported | Content-aware 003 (G15) | -| Windows checkout with `autocrlf`, `* text=auto`, LFS rules | Supported | `.gitattributes` (VERIFIED-ADV c2/V4). A surviving LFS rule is refused. | -| Packable library with a direct patched dependency | Supported with warning, or refused until G2 | §6.6 | -| Project outside the `.socket` root referencing a redirected project | Refused: `vendor_nuget_external_consumer` | VERIFIED-ADV e8 | -| Non-SDK csproj with PackageReference | Refused: `vendor_nuget_non_sdk_project` | REASONED (no mono) | -| Mixed packages.config and SDK on the same id@V | Refused: `vendor_nuget_mixed_project_styles` | Q5 | -| packages.config only | Legacy layout | | -| Property-expanded version on SDK < 8, or `global.json` SDK missing | Refused | REASONED | -| Implicit SDK references (FSharp.Core) | Refused | REASONED | -| 4-part non-zero or prerelease upstream | Refused until G5 | | -| `require` policy visible | Refused (fallback tier) | Feed tier is post-prototype | -| Submodules, template content | Skipped with warning | | - -## 9. Failure modes - -| Situation | Result | Loud? | -|---|---|---| -| Seed file missing or added (for example planted `build/*.props`) | SOCKETPATCH001 at restore, before `nuget.g.*` is regenerated on a clean checkout | Yes (G13) | -| Seed file edited | SOCKETPATCH002 at restore and build | Yes | -| All of `.socket/vendor/nuget` missing | SOCKETPATCH007 at restore (prototype, VERIFIED in the e2e), then MSB4019 at build | Yes | -| Only `socket-patch.targets` missing | Restore **succeeds and rewrites locks to upstream** (V3). Build gives MSB4019, and `--check` fails. | Build only; the CI gate is `--check` | -| V′ elsewhere, different bytes | SOCKETPATCH003. NU1403 applies only if `.nupkg.metadata` differs (VERIFIED-ADV x2). | Yes | -| V′ elsewhere, same bytes | Accepted | — | -| New or renamed project that imports the targets | SOCKETPATCH005, and NU1004 when locked | Yes | -| New nested DBP that does not chain to the root | **Silent at build** (VERIFIED-ADV x3, DBT analogue). Caught by `--check` import evaluation. | CI gate | -| Redirect engaged but drifted (bot edit, parent bump, NU1603) | SOCKETPATCH006 | Yes | -| Bot bumps the declared version | Redirect disengages; the lock diff shows V′ → new; `--check` flags the unused entry | In PR | -| Env var or package props setting `SocketPatchNuGetGuard=false` | Ignored (unconditional assignment) | — | -| Global `-p:SocketPatchNuGetGuard=false` | Guards off (escape hatch) | User choice | -| Planted `build/*.targets` on a dev machine that already restored | Arbitrary code before the guard; residual risk | Accepted; mitigated by `--check --online` in CI | -| Design-time build | Redirects apply; the guard is skipped | — (G16) | -| Docker `COPY *.csproj` without DBP/.socket | Locked: NU1004. Lockless: SOCKETPATCH005 at full build. `vendor` warns `vendor_nuget_dockerfile_copy`. | Yes | -| Sparse checkout without `.socket/` | NU1301/MSB4019. The block comment names `git sparse-checkout add .socket/vendor/nuget`. | Yes | -| CI-only `require` policy | Silently bypassed; closed by depscan org policy #6 | No (accepted gap) | -| NuGetAudit when V′ is still in an advisory range | NuGetAuditSuppress (NuGet ≥ 6.11). Older SDKs emit info `vendor_nuget_audit_still_flags`. | Parity with pre-patch | -| SBOM and dependency-graph tools reading locks | They see V′; depscan mapping (#4); document Dependabot alert behaviour | Docs | -| Missing seed + VS nomination restore + lockless + attacker feed serving V′ | Possible code execution | Accepted residual. Server gap check covers org upstreams. | - -## 10. Signing and enterprise policy (feed tier; post-prototype) - -- **Fallback tier:** it never claims signature enforcement. It refuses under a visible `require`, never writes `accept`, and never sets `DOTNET_NUGET_SIGNATURE_VERIFICATION`. -- **Feed tier:** - - Builder 0 only, so shared GPFs stay safe (adv-integrity M4). - - It adds exactly one `` for the per-uuid feed. Id-exact mapping is added only where a repo mapping already exists. It refuses with `vendor_nuget_feed_mapping_conflict` when the only mapping is outside the repo and the repo uses several versions of the id. - - **Trust:** it never writes a pfx-holder `` to repo config by default. The default path is depscan's CA-issued certificate plus RFC3161 timestamp (#8), trusted once at org or machine level. The opt-in `--nuget-sign-ephemeral` generates a per-uuid key, signs, destroys the key, then writes the fingerprint, so trust covers exactly the bytes already signed. `--check` flags unrecorded trustedSigners. - - **Guard:** the same content-aware 003/002 as the fallback tier. - - Gated by G6. - -## 11. Compatibility - -### 11.1 Hosted -- Unchanged until WS1 (`hosted_revert_unsupported`). -- Later, hosted can serve V′ from v3 and reuse the targets file. -- Independent fix: version-precise hosted lock matching at `redirect/mod.rs:5431`. - -### 11.2 Repair and sweep -- WIRING_FILES gains the three `nuget.config` spellings, the discovered DBP and DBT files, and `packages*.lock.json`. -- Reserved names: `socket-patch.targets`, `.gitignore`, `.gitattributes`. -- A wiring file that names a uuid directory makes that directory live. - -### 11.3 Older binaries (v4.0.0 is released) -- **The risk (REASONED from code).** Without mitigation, v4's revert deletes the seed while the locks and targets still reference it. v4's vendor applies a legacy layout on top. -- **Mitigations:** - - The literal `.socket/vendor/nuget/` comments in the root DBP block, plus a `nuget_uuid_anchor` record, make v4's drift-keep keep the seed and the entry (fail-safe). - - The v5 hybrid router (§5) and a heal step: detect a legacy `socket-patch-` source next to a fallback seed, remove it, and restore the lock. - - `revert_nuget_opts` fails closed on an unknown flavor (v5). - - The minimum version is documented. -- **Test:** G14 runs the real v4 binary against a fallback repo. - -## 12. Server/CLI split (depscan) - -| # | depscan addition | Needed for | -|---|---|---| -| 1 | `lib/src/nuget/socket-version.ts` derive/parse, with golden vectors shared with Rust | GA | -| 2 | `nuget-socket-version` repacker (V′ nuspec, STORE-only, deterministic, write-once). Refuses versions in (V, V′] on nuget.org **and the org's configured upstreams**. | GA | -| 3 | `artifacts[].kind="nupkg-socket-version"`, `nugetPatchedVersion`, `upstreamContentHash`, `upstreamSha512` | **GA** (provenance, drift repair, `--check --online`) | -| 4 | SBOM mapping V′ → upstream purl plus uuid; recognise the fallback folders. Bump task versions, run `generate-task-metadata`, use `RunTask` helpers. | **GA blocker** | -| 5 | Fixed-advisory GHSA list per patch (NuGetAuditSuppress) | Prototype nice-to-have; the CLI can fall back to local advisory data | -| 6 | Org `nugetSignaturePolicy: require` | GA for enterprises | -| 7 | `nuget-seed` artifact (extracted layout plus inventory), tested with real dotnet | Post-GA | -| 8 | CA-issued Socket author signing plus timestamp | Feed tier | -| 9 | Hosted V′ in flat and registration indexes | Later | - -Identity and bytes (about 30% of the logic) belong to the server. All repo and machine wiring is 100% CLI. - -## 13. Test plan - -**Hermetic unit tests** (`cargo test -p socket-patch-core --lib nuget_`): -- `nuget_version`: vectors, round-trip, gap refusal. -- `nuget_lock`: goldens from real `--force-evaluate` output for `[V′, )`, covering: - - each role, including CentralTransitive with pinning on, range-consumers and canonical Direct ordering; - - CRLF and no trailing newline; - - RID goldens for a `runtimes/` package (SqlClient); - - EOL-neutral revert and drift. -- `nuget_targets`: render golden with uppercase-hex pinning; XML and MSBuild escaping; DBP block inject and excise on CRLF, BOM, ``, chained DBPs; stub rendering. -- `nuget_seed`: decode-then-validate traversal cases (`%2E%2E%2F`, `%5C`), metacharacter refusal, case-fold collisions, OPC drops, `reversion_nupkg` determinism. -- `nuget_projects`: closure on fixtures (e2 AppA/AppB/AppC, multi-TFM e3, external consumer e8, spellings e9, submodule, template). -- `nuget_policy`: chain merge. -- `sync_shared`: update, revert order, Preserved, dry run. - -**Real-dotnet e2e** (`e2e_nuget_dotnet_build.rs`; SDK 6–10 ubuntu, 8 macOS, **windows-latest**). Legs: -- `sln_locked`, `cpm_locked`; -- warm GPF; -- `RestorePackagesPath`/`NUGET_PACKAGES`; -- `locals --clear`; -- tamper (002) and planted file (001); -- env-var disable ignored; -- pack (range restore, 004 pre and post, output deleted); -- revert plus `git diff --exit-code`. - -**Docker** (`docker_e2e_vendor_nuget.rs`): -- static graph; no lockfile; -- 005 rename; 006 bot edit; -- anchor NU1301; `--packages` then `--no-restore`; -- hostile user mapping; -- require refusal; -- migration plus eviction; -- idempotence; -- G3 two roots; -- e2/e3/e7/e8 fixtures; -- same-bytes V′ in the GPF (003 passes) and different bytes (003 fails); -- patch update A→B then revert; -- two-id revert in both orders; -- crash between write and save (resume via `sync_shared`); -- v4 binary (G14); -- parallel `-m`; -- mono image for the packages.config refusal. - -**Real-clone legs** (prototype acceptance): commit, `git clone`, build under `* text=auto`, `autocrlf=true`, a `*.dll filter=lfs` root rule, and sparse checkout. - -**Regression:** every existing `nuget_feed` test passes unchanged with the default layout. - -## 14. Gating experiments and open questions - -| ID | Question | Blocks | -|---|---|---| -| G1 | Content-aware guard with multiple roots; `@(Analyzer)`; analyzer-only and build-only packages via the assets `libraries` | Prototype | -| G2 | Pack pre/post checks and `@(NuGetPackOutput)` deletion on SDK 6–10 | Packable support | -| G3 | Multiple uuid roots plus the anchor root together | Prototype | -| G4 | SOCKETPATCH005/006 on renamed projects (001 is VERIFIED-ADV) | Prototype | -| G5 | Prerelease-tagged V′ forms | 4-part/prerelease | -| G6 | Feed tier with V′ under `require`; shared GPF across repos | Feed tier | -| G7 | Static graph plus `dotnet test` across CPM variants | Promotion | -| G8 | macOS/Windows path case; nuget.exe packages.config | Promotion | -| G9 | VS/Rider design-time restore honours redirects | Docs | -| G10 | `CustomAfterDirectoryBuildTargets` on SDK 6/7; chained-DBP dedupe | **Prototype** | -| G11 | `[V′, )` lock goldens, TFM-conditioned pins, no NU1603 when the seed is present | **Prototype** | -| G12 | The anchor fallback folder gives NU1301 at restore when `.socket/vendor/nuget` is missing, and nothing when present | **Prototype** | -| G13 | Restore-time set check: glob includes dotfiles, runs under static graph, runs before a planted `build/` file on a clean checkout | **Prototype** | -| G14 | v4.0.0 revert and vendor against a fallback repo keep the seed (fail-safe) | **Prototype** | -| G15 | `SpKeyPath` computation for GPF-resolved files | Prototype | -| G16 | Guard skipped when `DesignTimeBuild=true` in VS, Rider and C# Dev Kit | Promotion | -| Q1 | Should SOCKETPATCH005/006 be warnings for one release? | Product | -| Q2 | Is org require policy (#6) enough, or should the feed tier be default for paid orgs? | Product | -| Q3 | Renovate and Dependabot behaviour on the targets file; emit `ignorePaths: [".socket/**"]`? | Docs | -| Q4 | Re-vendor builder-1 seeds to builder 0 once the service artifact ships? | Post-GA | -| Q5 | Dual wiring (legacy for packages.config plus fallback for SDK) for mixed repos? | Post-prototype | - -## 15. Prototype scope - -**Goal.** A working prototype for SDK sln with locks in locked mode, and for CPM, with no change to default behaviour. - -**Gating.** -- `--nuget-layout` on `GlobalArgs`, with the inference rules from §5. -- `layout_for(entry, state, run)` is used by `dispatch_vendor_one` (callers at `vendor.rs:2636` and `repair_vendor.rs:1632`, and via `vendor_records`). -- `service_preflight` changes signature to take `&VendorState`. -- The revert arm uses the hybrid router. - -**In scope:** -- Fallback tier; 3-part V′. -- All roles, including range-consumers. -- The DBP block, the anchor, and `sync_shared`. -- `.gitattributes` with probes. -- Guards 001–006 and the pack checks. -- NuGetAuditSuppress. -- Hot path, `--check` (including `--online`), revert. -- Patch update. -- The pristine fetch rung. -- VEX extractor, crawler skip, in-use probe. -- v4 anchor and hybrid router. -- Flavor gate, WIRING_FILES, sweep. -- Name validation and escaping. - -**Out of scope:** the feed tier and signing; 4-part and prerelease upstreams; packages.config (legacy, and mixed repos are refused); `--nuget-relock`; migration (refused with `vendor_nuget_layout_mixed`); hosted, apart from the `:5431` fix. - -**Modules** (under `crates/socket-patch-core/src/vendor/` unless noted): - -| Module | Items | -|---|---| -| `nuget_version.rs` | `NugetBuilder`, `SocketNugetVersion`, `socket_nuget_version`, `parse_socket_nuget_version`, `check_version_gap` | -| `nuget_projects.rs` | `NugetProject`, `discover_projects` (`*.*proj`, sln, worktree-bounded), `plan_closure` (V′-aware, bidirectional), `ProjectRole::{Direct, CpmUniform, CpmSplit, AutoFollow, Pin{tfm_alias, parent}, RangeConsumer}`, `excluding_constraints`, `external_consumers` | -| `nuget_lock.rs` | `LockEntryEdit`, `plan_lock_edits`, `splice` (EOL-aware), `revert_lock_entry_record`, `semantic_eq` | -| `nuget_seed.rs` | `reversion_nupkg`, `extract_seed` (decode then validate), `seed_inventory`, `walk_seed_strict`, `write_seed_atomic` | -| `nuget_targets.rs` | `render_targets`, `render_gitignore`, `render_gitattributes`, `render_dbp_block`, `inject_block`, `excise_block`, `msbuild_escape` | -| `nuget_shared.rs` | `sync_shared(cwd, &VendorState, dry_run)` | -| `nuget_policy.rs` | `effective_signature_mode` | -| `nuget_fallback.rs` | `vendor_nuget_fallback`, `revert_nuget_fallback_opts`, `service_preflight`, `fallback_prelude`, `fallback_in_sync`, `layout_for`, `fetch_pristine` | -| `state.rs` | `NugetMeta` (with `wired`, `literals`, `allowUnpatched`, upstream hashes), `nugetLayout`, `nugetShared`, `fileInventory` intactness in `ledger_covers` | -| `ledger_snapshots.rs`, `path.rs`, `verify.rs` | new kinds; uuid8 nested leaf parser; reserved names; set-equality verify | -| `nuget_feed.rs` | flavor gate; `CONFIG_NAMES` | -| `crawlers/nuget_crawler.rs`, `vex/discover/nuget.rs`, `vex/discover/mod.rs:1750` | skip seeds; fallback extractor; probe files | -| CLI `vendor.rs`, `rollback.rs`, `remove`, `gc`, `repair_vendor.rs`, scan/get | `sync_shared` calls; `vend_installed!` fix; in-use probe; `GlobalArgs` flag | - -The CLI and VEX work adds roughly 30–40% over the revision 1 estimate. - -**Prototype acceptance:** -- the §13 unit goldens; -- sln and CPM e2e on SDK 6–10, plus Windows and macOS; -- the docker suite and the real-clone legs; -- G1, G3, G4, G10–G15; -- zero changes to existing NuGet test outcomes. - -**Promotion to default** additionally requires G2, G7, G8 and G16; depscan #2–#4; and one release as opt-in. - -## 16. Adversarial review - -Dispositions: **Fixed** (design changed), **Refused** (moved to refused shapes), **Accepted** (risk kept, with rationale), **Open** (gating experiment or question). - -### Shapes -| ID | Finding | Disposition | -|---|---|---| -| S-B1 | `[V′]` spreads via ProjectReference (NU1107, NU1608, NU1004 outside the closure) | **Fixed:** `[V′, )`, SOCKETPATCH006, range-consumer lock edits, gap check (§6.1, §6.4, §6.5). Goldens G11. | -| S-B2 | Once-guard on a chained DBT imports too early; pin gives NU1504 | **Fixed:** DBP `CustomAfterDirectoryBuildTargets` (§6.3). SDK 6/7 is G10. | -| S-B3 | autocrlf breaks the seed | **Fixed:** generated `.gitattributes` plus `check-attr`; LFS refused (§6.2) | -| S-M1 | Pins not TFM-conditioned | **Fixed:** alias condition from assets; unknown alias refused | -| S-M2 | Consumer outside the root breaks, or goes silent under `[V′, )` | **Refused:** `vendor_nuget_external_consumer`; 006 covers in-root drift | -| S-M3 | 004 fires after the nupkg is written | **Fixed:** pre-check plus deletion of `NuGetPackOutput` (G2) | -| S-M4 | Several nuspecs give MSB4184 | **Fixed:** exact nuspec path | -| S-M5 | Non-SDK PackageReference projects are unguarded | **Refused:** `vendor_nuget_non_sdk_project` | -| S-M6 | NU1903 still fires on V′ | **Fixed:** §2.3 corrected; NuGetAuditSuppress in prototype; info code on < 6.11 | -| S-M7 | Literal spellings, `*.proj` types, SDK < 8 `-getItem` | **Fixed:** one condition per spelling, `*.*proj` plus sln; SDK < 8 property versions and missing SDK refused | -| S-minor | CPM golden, canonical order, per-package seed hashing, exact literal in pack, implicit refs, tool wording, RID goldens, MAX_PATH, analyzers | **Fixed:** §6.5, §6.6, §7.1, §13, uuid8. Seed hashing moved to a once-per-restore check (`_SpSeedChecked`). Analyzers are G1. | - -### Environments and CI -| ID | Finding | Disposition | -|---|---|---| -| E-B1 | EOL normalization fails fresh clones | **Fixed:** `.gitattributes`, `--check` against HEAD blobs, `ls-files --eol`, clone legs in acceptance | -| E-M1 | Same-bytes V′ in the GPF fails 003 with destructive advice | **Fixed:** content-aware 003, `/` keys, new message (G15) | -| E-M2 | Guard runs in design-time builds | **Fixed:** `DesignTimeBuild` condition; §9 corrected (G16) | -| E-M3 | Windows path depth | **Fixed:** uuid8 directory, absolute-path check with refusal, Windows leg in prototype | -| E-M4 | EOL-sensitive comparisons | **Fixed:** generated files `-text`; EOL-neutral records and splices | -| E-M5 | Mixed packages.config/SDK undefined | **Refused:** `vendor_nuget_mixed_project_styles`; dual wiring is Q5 | -| E-M6 | `--check` needs restore outputs | **Fixed:** persisted closure is authoritative; unrestored applies only to new projects | -| E-M7 | Renovate/Dependabot edit the targets | **Fixed:** property-indirected versions, render sha, 006 catches edits. Q3 stays open. | -| E-minor | Sparse checkout, Docker COPY, `git clean`, seed size, case collisions, predictable-V′ attack, SBOM alerts, setup-dotnet cache, concurrency | **Fixed/Accepted:** block comment; `vendor_nuget_dockerfile_copy`; untracked-seed check; size caps; case-fold refusal; server gap check over org upstreams (residual accepted, §9); depscan #4; dot-directory skip; no fix needed for concurrency | - -### Integrity -| ID | Finding | Disposition | -|---|---|---| -| I-B1 | Seed file set unpinned; planted files disable the guard; lock pins nothing | **Fixed:** restore-time set and hash check (G13), strict CLI walk, `--check --online`, unconditional guard. §1 wording narrowed. **Accepted residual:** a dev machine that already restored a planted seed runs its code; CI `--online` is the defence. | -| I-B2 | Git transforms seed bytes | **Fixed** (same as E-B1) | -| I-M1 | Env var, props or rsp disable the guard | **Fixed:** unconditional assignment (VERIFIED-ADV x1), CLI allowlist, rsp flagging | -| I-M2 | New nested DBT hides the import silently | **Fixed/Accepted:** `--check` evaluates every project's import; documented as the CI gate. Build-time silence is accepted. | -| I-M3 | GPF V′ beats the seed | **Fixed:** content-aware 003; §9 wording corrected; exact per-uuid root is no longer needed because keys are content-based | -| I-M4 | Builder 1 is not one byte sequence | **Fixed:** feed tier accepts builder 0 only. **Accepted** for the fallback tier: only lock churn. | -| I-M5 | Drift repair from a poisoned GPF | **Fixed:** repair only from depscan or a signature-verified download | -| I-M6 | Upstream provenance lost | **Fixed:** signature or sha512 check at vendor; `upstreamSha512` recorded; depscan #3 is GA | -| I-M7 | Repo-level pfx author trust is id-unscoped | **Fixed:** feed tier defaults to CA cert; ephemeral-key opt-in; `--check` flags trustedSigners | -| I-M8 | Percent-decoding traversal and MSBuild injection | **Fixed:** decode then validate, metacharacter refusal, escaping, strict validation at render | -| I-M9 | Analyzer and build-only packages unguarded | **Fixed:** `@(Analyzer)`, assets `libraries`, unconditional restore check (G1) | -| I-minor | Symlinks, late `require`, nuspec edits, §9 wording, stale obj, hex-case golden | **Fixed:** symlink refusal on ancestors; `--check` policy re-probe; set check; wording; test legs; golden | - -### Lifecycle -| ID | Finding | Disposition | -|---|---|---| -| L-B1 | Patch update renders both uuids, pins a dead V′, breaks revert | **Fixed:** `sync_shared` after persist and sweep; V′-aware planner; `original: None` carry-forward; replaced entry excluded (§7.5) | -| L-B2 | Import records lost across uuids, order and crashes | **Fixed:** state-owned block, record-free excision, blocks removed before the targets, stub on drift (§7.2) | -| L-B3 | Seed not byte-stable through git | **Fixed** (E-B1) | -| L-M1 | Preserved or Kept entries re-wired | **Fixed:** `wired` flag; missing seeds are never rendered | -| L-M2 | Revert order defeats drift-keep | **Fixed:** §7.4 order | -| L-M3 | No pristine source on clean machines; `debug_assert` panic | **Fixed:** fetch rung verified against ledger hashes; assert removed for fallback (§7.7) | -| L-M4 | Hot path and `--check` before restore; re-plan misreads V′ | **Fixed:** persisted plan; V′ decoded as V | -| L-M5 | v4 binaries corrupt fallback entries | **Fixed/Open:** literal uuid anchor, hybrid router, heal step; G14 | -| L-M6 | VEX silently drops fallback patches | **Fixed:** extractor and probe files in prototype scope | -| L-M7 | Unsafe unwind of shared outputs and reused seeds | **Fixed:** staged writes, snapshots, delete only what this run created | -| L-M8 | Migration destroys its own source | **Fixed:** prelude first, re-version the committed legacy nupkg, one atomic unit (§7.6) | -| L-M9 | Restore does not fail closed on a missing targets file | **Fixed/Accepted:** anchor NU1301 when `.socket` is gone (G12); targets-only deletion accepted, with `--check` as CI gate; §9 corrected | -| L-M10 | Transitive pins keep themselves alive | **Fixed:** pin conditioned on the direct parent; in-use probe excludes self-edges; `pin_orphaned` | -| L-M11 | Layout choice does not persist | **Fixed:** `GlobalArgs` flag, inference, `nugetLayout` | -| L-P1 | Prototype needs CLI hooks not in §15 | **Fixed:** §15 scope and module table extended (+30–40%) | -| L-minor | User edits of the targets, submodules/templates, builder churn, dry run, directory `ledger_covers`, NU1903 | **Fixed:** render sha plus `targets_edited`; worktree bound plus skip; builder sticky; in-memory render; inventory intactness; S-M6 | - -## 17. Prototype (follow-up branch `v5/nuget-vendoring-prototype`): what was built and how it deviates - -**Code:** `crates/socket-patch-core/src/vendor/nuget_{version,seed,lock,targets,fallback}.rs`, plus small routing hooks in `vendor/mod.rs`, `commands/vendor.rs` and `commands/repair_vendor.rs`. - -**Tests:** -- unit tests in each module; -- lock fixtures captured from real `dotnet` in `crates/socket-patch-core/tests/fixtures/nuget-fallback/{sln,cpm,cpmpin,cpm-tool}`. NuGet's own `--force-evaluate` output is the golden for the splice; -- `crates/socket-patch-cli/tests/e2e_nuget_fallback_dotnet.rs`, which is `#[ignore]` and runs against the real SDK and nuget.org. Its legs are `sln_locked`, `cpm_locked`, `cpm_pinning` and `sln_patch_update`. - -The default layout is unchanged: every existing NuGet test passes untouched. - -Implementation: `crates/socket-patch-core/src/vendor/nuget_{version,lock,seed,targets,fallback}.rs`. - -### Behaviour deviations (deliberate) - -1. **Lock rule for a range at V that resolved elsewhere.** The spec only edits entries whose `resolved` is V. NuGet also rewrites `requested "[V, )"` → `"[V′, )"` on a `CentralTransitive` (or `Direct`) entry that resolved to some other version (cpm-tool `Tool`: `resolved 12.0.1`). Without this edit, `--locked-mode` fails NU1004. The splice now makes the requested-only edit (`resolved` and `contentHash` are left unchanged), and the golden `cpm-tool` fixture proves it. -2. **`CentralTransitive` at V counts for transitive-only too.** Under CPM *without* pinning, a `CentralTransitive` V entry is refused `vendor_nuget_transitive_only` when the project has no `Project` reference to a redirected project. This follows from NuGet itself: without pinning the central version is not applied, so the entry resolves upstream V and the build guard would fire. With `CentralPackageTransitivePinningEnabled` it is redirected. Pinning is detected by a repo-global text scan. -3. **Layout selection is per purl.** The env var or any `nuget-fallback` ledger entry selects the fallback layout, except for a purl the ledger already holds as a legacy feed entry: that purl keeps routing to `nuget_feed` (vendor and service preflight), so an in-sync legacy entry never fails `vendor_nuget_layout_mixed` once the repo opts in. The refusal stays in the backend for direct callers. The earlier "targets file exists" signal was dropped: `.socket/` writes are outside the group commit, so a failed or crashed run could leave the targets behind and silently opt the repo in. -4. **DBP block text.** - - The begin comment is `(generated; remove with: socket-patch vendor revert)`. An XML comment cannot contain `--`, and a DBP that fails to load is silently ignored by restore. - - `` is rendered with its trailing slash (`""` / `../`), which gives `$(MSBuildThisFileDirectory).socket/...` and never `//.socket`. - - **The anchor line is gone.** Registering `.socket/vendor/nuget` itself as a fallback folder let anyone plant `//` beside the uuid dirs and have NuGet restore it under `--locked-mode` with no seed check (security review, reproduced on SDK 8). The block now holds a `SocketPatchNuGetImportCheck` target instead (`BeforeTargets="_GenerateRestoreGraph;CollectPackageReferences"`, condition `'$(SocketPatchNuGetTargetsImported)' != 'true'`), which fails restore with **SOCKETPATCH007** when the targets were not imported (the vendored tree is missing; restore ignores the missing import). The e2e proves it for locked and unlocked restore. `-p:SocketPatchNuGetGuard=false` disables it like the other guards. - - A props file socket-patch **created** carries `socket-patch:begin created` on its begin line. Only such a file is deleted on the last revert, when nothing but its block was added (compared with BOM and CRLF normalised). A user's own `\n\n` is kept, and a CRLF checkout of a created file is still deleted. Re-rendering a block keeps the tag. - - The `` insertion point (and a self-closing ``) is found with comments blanked, so a `` inside a trailing comment is never used. -5. **The render inputs live in the marker.** - - `socket-patch.vendor.json` gains an optional `nuget` section: `id`, `version`, `socketVersion`, `contentHash`, `spellings`, `inventory`, and `wired` (default true). - - `sync_shared` renders the seed inventory from the marker, never from the disk, so a tampered seed is never re-baselined. - - The marker is not trusted alone: when the ledger has a `nuget-fallback` entry for the uuid, its `artifact.file_inventory` replaces the marker's inventory in the render. The one exception is the seed the current vendor run just wrote (`RenderScope::fresh`). The markers are also diffable in `.gitattributes` (`/*/socket-patch.vendor.json -text diff`), so a changed hash shows in review. - - The `AlreadyPatched` fast path also requires every patched file in the seed to hash to its `afterHash`. - - A `--preserve-state` revert (`keep_artifact`) writes `wired: false`. The seed stays on disk but is no longer rendered into the targets. -6. **Extra refusal codes** beyond the spec list: - - `vendor_nuget_nuspec_patched`: the patch rewrites the root nuspec, which the layout re-versions. - - `vendor_nuget_version_literal_unknown`: a `$(Property)` or item version for the id. - - `vendor_nuget_lock_unreadable`: an unparseable or unreadable lock. - - `vendor_nuget_seed_failed`: the canonical zip failed. - - `vendor_nuget_symlink_unsupported`: a project file, `Directory.Build.props` or `packages.lock.json` under the root is a symlink (an atomic rewrite would replace the link, and a skipped linked props file would silently shadow the wiring). `sync_shared` and revert refuse the same way before writing anything. - - `vendor_nuget_repo_too_large`: the discovery walk hit its 100,000-entry cap. Vendor refuses, and `sync_shared` / revert fail before writing, instead of silently wiring only part of the tree. - - Coordinates containing `--` refuse `unsafe_coordinates` (they are rendered into XML comments); `.` / `..` and `--` never render from a marker either. - - Floating (`*`) or bracketed ranges naming V in csproj/props text refuse `vendor_nuget_range_unsupported`, the same code as lock ranges. -7. **Member-name validation.** - - Names are percent-decoded first. - - They must then pass `is_safe_relative_subpath` + `is_plain_archive_name` + `names_are_unambiguous` (printable ASCII; no `\ : * ? " < > |`; no case-fold collisions). - - Names containing `$ @ % ; '` are refused instead of escaped. - - Members named `.nupkg.metadata`, `*.nupkg` or `*.nupkg.sha512` are refused. - - OPC parts (`[Content_Types].xml`, `_rels/`, `package/`) and `.signature.p7s` are dropped, compared case-insensitively. - - The nuspec `` must match the purl id. -8. **`vendor_nuget_no_lockfile`** is emitted when **no** discovered `packages.lock.json` references the id (at V, V′ or an older Socket version of V), not per project. -9. **Signature policy is conservative.** - - The CLI refuses if *any* config sets `signatureValidationMode=require`. It checks every dir from each SDK project dir up to the root, the root and its ancestors (all three config spellings), `~/.nuget/NuGet/NuGet.Config`, and `%APPDATA%/NuGet/NuGet.Config`. - - NuGet's nearest-wins override is not modelled, and `DOTNET_NUGET_SIGNATURE_VERIFICATION` is not read. -10. **contentHash bytes.** The canonical zip is built with the existing `write_zip_entries` (zip-crate deflate level 6, fixed DOS time, mode 0644), so its hash differs from the Python-built fixture hash (`DDiM…`). NuGet only string-compares lock ↔ `.nupkg.metadata`, and the real-dotnet e2e proves the Rust value works. -11. **Wiring record shape and per-entry revert.** - - One `nuget_lock_file_v2` record per lock that pins the id after the splice (edited now or already spliced): `key` is the id, `original` and `new` hold the whole text. Recording unchanged-but-spliced locks keeps their revert across a partial re-vendor. - - The kind is registered in `ledger_snapshots::WHOLE_FILE_KINDS`, so large `new` values are diff-encoded (ledger version 2). - - When the pre-edit lock already names a Socket version of V anywhere (a re-vendor, same or older uuid), `original` is `None` and `carry_forward_wiring` fills it from the replaced entry. - - **The revert does not restore whole files.** `nuget_lock::unsplice_lock` puts back only this entry's values (V′ in `resolved`, `requested`, Project `[V′, )` ranges, and the matching `contentHash`), each to the value the recorded `original` held at the same JSON path (else plain V / `[V, )`; a hash only from `original`). Another seed's splice, a package or framework added since, and EOLs are untouched, so seeds sharing a lock revert in any order and a stale carried-forward original cannot discard later edits. When no upstream hash is recorded the entry is left at V′ and reported `vendor_lock_entry_drifted` (the seed is then kept). -12. **Seed rebuild.** An existing but stale seed dir for the same uuid is rebuilt through `.socket-stage` + `swap_stage_into_place`. If a later step fails, the unwind deletes the seed only when this run created it, so a replaced stale seed is not restored. -13. **Self-closing `` DBP.** It is expanded to `…`, and excision leaves `\n` rather than byte-restoring the self-closing spelling (the file is kept, never deleted, since socket-patch did not create it). The same applies to a `` sharing a line with other content, where one extra EOL remains. -14. **Seed materialisation.** - - The new `nuget_feed::patched_nupkg_bytes` wraps the unchanged `materialise_patched_nupkg` (service download → local rebuild) in a private temp stage. - - `config_wired=true` is passed only so a failed build does not prune the stage's parents. - - The seed is then extracted from those same-version bytes. -15. **Patch update (new uuid).** `splice_lock` treats any value at an *older* Socket version of the same V (resolved, requested, Project range) as a re-splice target and moves it to the new V′ and hash. The vendor run leaves the superseded uuid's seed out of the render (`RenderScope::exclude`), and the CLI re-runs `sync_shared` after `sweep_stale_artifact` deletes the old uuid dir. The new `sln_patch_update` e2e leg proves the flow with real dotnet. - -### Verified with real dotnet (SDK 8.0.131, nuget.org) -`e2e_nuget_fallback_dotnet` covers `sln_locked`, `cpm_locked`, `cpm_pinning` and `sln_patch_update`. The first three each do the following: -- runs the real `socket-patch scan --mode vendored --vendor-source build` with `SOCKET_PATCH_NUGET_LAYOUT=fallback`; -- on a fresh copy, runs `restore --locked-mode` with a cold GPF: the locks are unchanged and the App (and Tool) bin dll carries the patched bytes; -- does the same with a warm GPF that holds upstream 13.0.1; -- tampers a seed file and checks for `SOCKETPATCH002`, then restores the committed bytes and checks that restore passes; -- removes `.socket/vendor/nuget` from a checkout and checks that locked and unlocked restore fail `SOCKETPATCH007`; -- re-runs vendor **without** the env var (the ledger alone selects the layout) and checks that no project file changes; -- runs `vendor --revert` without the env var and checks that the tree outside `.socket/` is byte-identical and no `.socket/vendor/` remains; -- runs a locked restore and build of the reverted tree and checks that the pristine dll is back. - -`sln_patch_update` vendors uuid 1, then a newer patch (uuid 2) without the env var, and checks: no `vendor_nuget_no_lockfile`, both locks at V′₂ only, the targets name only uuid 2, the uuid 1 dir is gone, a cold locked restore leaves the locks unchanged and builds the uuid 2 bytes, and `vendor --revert` restores the pre-vendor tree byte for byte. - -### Known gaps (out of scope / follow-ups) -- The following are not implemented: - - SOCKETPATCH003/004/006, pack range restore, per-project transitive pins, packages.config, the feed tier and signing, migration from the legacy layout (refused as `vendor_nuget_layout_mixed` for the same purl only), and `--check`. - - Post-write git probes: `vendor_artifact_gitignored` / `_git_transformed`. - - Long-path warning, size caps beyond the existing zip-bomb caps, and the version-gap/collision checks against nuget.org. -- **Lock discovery** reads only `/packages.lock.json`. `NuGetLockFilePath` and `packages..lock.json` are ignored. -- **Version literals** are found only as `Version=` attributes or `` children of `PackageReference` / `PackageVersion` / `GlobalPackageReference` in `*.csproj|fsproj|vbproj|props|targets` text. MSBuild evaluation is not used. -- **DBP placement** only considers DBPs inside the root. A `Directory.Build.props` *above* the repo root that a project relied on is shadowed by the created root DBP, because the created file does not import the parent. -- **Repair.** It can re-synthesise a fallback entry from the targets file (flavor stamped `nuget-fallback`), but not its lock wiring records. A revert of such a reconstructed entry deletes the seed and leaves the locks spliced. -- **Service download path.** Every e2e vendor uses `--vendor-source build`; the fallback's use of a downloaded service artifact (`patched_nupkg_bytes` → service copy, fallback `service_preflight`) is covered only by unit tests of the shared feed pipeline. -- **SOCKETPATCH005** (the build guard) is not exercised by the e2e. -- **Marker trust.** A uuid dir with no ledger entry (state.json lost, or before the entry is committed) still renders from its own marker. -- **Orphan sweep.** It now treats uuid dirs named in `socket-patch.targets` as wired. -- **Migration.** A purl held by a legacy feed entry keeps the feed layout even with the env var set; migrating it needs a `vendor --revert` first. -- **VEX.** There is no fallback extractor. Discovery returns nothing for fallback repos (the golden `vex-discover-golden/nuget-fallback.json` records empty results; there is no crash). Ledger-based VEX verifies the seed dir through the existing dir-artifact path, members plus `fileInventory`. -- **Crawler.** After a restore, `obj/project.assets.json` lists the fallback folder as a package folder, so the crawler may report `newtonsoft.json@13.0.1.` as an installed package. This is not mapped back to the upstream purl. -- **Pre-existing failures, unrelated.** - - `cargo clippy --workspace --all-targets --all-features -- -D warnings` fails only in the untouched `crates/socket-patch-cli/tests/covgap_commands_rollback.rs:152` (dead fields `before_hash`/`after_hash`). - - 9 core lib tests fail in this environment regardless of this change (it runs as root: read-only-permission tests and an RSS measurement). - - `cargo fmt --all` reformats ~75 unrelated files on HEAD. Those changes were reverted; only the files touched here are rustfmt-clean. - diff --git a/docs/design/repacking-to-depscan.md b/docs/design/repacking-to-depscan.md deleted file mode 100644 index a8f5acc7f..000000000 --- a/docs/design/repacking-to-depscan.md +++ /dev/null @@ -1,1014 +0,0 @@ -# Repacking moves to depscan (server-primary, one local class) - -> Reference copy of PR #286, which was closed without merging. Each -> finding's owner (workstream, in-flight PR or owner decision) is in -> the [triage map](https://github.com/SocketDev/socket-patch/pull/286#issuecomment-5869109317). - -Status: chosen design, pending owner sign-off on the open questions (last -section). Baseline: socket-patch `release/v5-prerelease` at 8ae7dc37, -depscan `master` at 93e149c9ba. Supporting evidence: the repacking inventory -of both repos and the verified waste findings (cited as F01–F80). Line -numbers are at those baselines; depscan paths carry a `depscan:` prefix. -Where a claim rests on an in-flight v5 branch, the branch is named. - -## Summary - -- **depscan becomes the producer of installable patched bytes** for every - vendorable ecosystem except maven/nuget (frozen, unchanged). The CLI - resolves, downloads, verifies, and wires. It computes no lock pin except - the one class below, and a pin it does compute is always cross-checked - against the server's value where one exists. -- **Exactly one local builder stays**: the pypi wheel built from the - installed dist (`pypi_wheel.rs`). It runs only when the server returns a - terminal `refused { localBuild: "allowed" }` verdict: releases with no - servable wheel for the requested tags (the installed binary was - necessarily built on the user's machine), or an upstream file over the - serve cap. The verdict is keyed on (uuid, requested wheel) and carries a - TTL, because PyPI can add wheels to a release later; the ledger's - `producer` keeps the choice sticky. It never runs because of an outage. -- **One producer per artifact, and the ledger keeps it sticky.** Vendor - `state.json` records `producer`, `recipe`, `generation`, and - `statementDigest`. Outages, 5xx responses and `pending_build` fail - retryably and leave the lock untouched. The integrity flip that #250 and - `reuse.rs` exist to hide can no longer happen. Reuse stays, as the - network-free re-run path. -- **Contract v2 is additive, on the existing endpoint** `POST - /v0/orgs/{slug}/patches/package` (and its anonymous twin `POST - /patch/package`). It adds per-uuid `refused`, `format`, `generation`, - `retryAfterSeconds`, pypi wheel variants, and a detached signed - statement (DSSE over JCS). Offline use gets a content-addressed user - cache and a signed export bundle. v1 stays schema-compatible: the only - changes are `yarn-berry-zip.url` becoming null and an additive - `yarnBerry10c0` on the tarball integrity. -- **Sequencing respects WS5.** Everything before step 24 is additive and - flag-gated. Flipping the default (step 24) and deleting the builders - (Phase 4; about 2,050 CLI src LOC and about 1,260 test LOC) both need - the owner to reverse the WS5 caveat after #283 merges; step 24 also - needs 30 days of telemetry. CI minutes saved: about 0. This is a - correctness and maintenance change, not a CI lever. The CI levers are - F51 (≈280 job-min), F41, F52, F53 and F55 (see v5-waste-review.md - Top-10); F78, which contains F63, is a transient saving during the v5 - draft train. - -## Current state - -### Who builds what - -LOC counts treat `#[cfg(test)] mod` as the boundary between src and test. -"Byte-identical" means the CLI's local build equals the server artifact. - -| Flavor (all PM versions stay) | Server artifact (depscan:workspaces/patches/src/repack) | Server src/test LOC | CLI local build | CLI build src/test LOC | Lock pin (vendored) | Byte-identical? | -|---|---|---|---|---|---|---| -| npm, pnpm 1–10 incl. legacy, bun.lock/bun.lockb | tgz, `repackers/npm.ts` (upstream order, mtime 0, zlib default; depscan:workspaces/patches-shared/src/archive/repack-utils.ts:597-660) | 557 / 467 (npm incl. berry) | `npm_pack.rs:73-177` (sorted, mtime 499162500, flate2 level 6) plus `npm_common.rs:248-396` stage branch | 177 / 247 plus about 149 | sha512 SRI | **No** | -| yarn classic | same tgz | — | same | — | sha1 `#hash` plus integrity | **No** | -| yarn berry | tgz plus `yarnBerry10c0` (`berry-cache-zip.ts`, a TS port of `berry_zip.rs`); `.berry.zip` sidecar stored and never read (F33) | 353 / 167 | `berry_zip.rs` recompute over the local tgz | 333 / 320 | `checksum 10c0/…` plus `hash=` (first 6 hex of tgz sha512, `yarn_berry_lock.rs:272-277`) | Recipe yes; input tgz differs, so **no** in practice | -| vlt | same tgz | — | `npm_dir.rs` `stage_patch_dir` local branch (about 594-730) | about 137 | none vendored (directory); hosted pins raw sha512 | n/a (extracted) | -| pypi: uv, poetry, pdm, pipenv, requirements, hatch | wheel only with `artifact_id`/`packaging=wheel` qualifier, else the sdist (`pypiPurlWantsWheel`); bz2/xz sdists refused after download (`repackers/pypi.ts:131-138`, F69) | 411 / 816 | `pypi_wheel.rs` from installed site-packages RECORD, Deflated zip | 696 / 1,288 | wheel sha256 | **No** | -| gem (Bundler, all eras) | `.gem` plus stub `.gemspec`; platform gems refused | 777 / 768 | `gem.rs` `materialise_patched_copy` (1192-1339) | 148 | none (PATH source, CHECKSUMS stripped) | n/a (extracted) | -| cargo (lock v1–v4) | `.crate` plus sparse-index line | 982 / 976 | `cargo.rs` `copy_and_patch` | 86 | none (path dep, `.cargo-checksum.json` dropped at `cargo.rs:394`) | n/a (extracted) | -| golang | module zip plus gopatch zip plus go.mod, dirhashH1; no-go.mod modules refused (depscan:…/repackers/golang.ts:109-115) | 792 / 485 | FallBack arm (`golang.rs` about 291-354) into `patch/redirect/golang_local.rs` (agent-mode code, stays) | about 64 | none (dir `replace`, no go.sum) | n/a (extracted, h1 verified) | -| composer | dist zip (STORE) | 308 / 352 | `composer_lock.rs` `copy_and_patch` | 60 | none (path dist) | n/a (extracted) | -| maven | jar (STORE) plus pom | 483 / 523 | `local_rebuild_jar`/`rebuild_jar_bytes` (Deflate, `maven_repo.rs:776-862`; the byte difference is shown by the test at :4112) | about 160 | `.sha1` sidecars | **No** (frozen) | -| nuget | nupkg (STORE, unsigned) | 167 / 187 | `nuget_feed.rs` `local_rebuild` | 130 | contentHash = b64(sha512) | untested (frozen) | - -Shared machinery: -- CLI side: - - `registry_fetch.rs`: 2,316 src and 2,914 test LOC. It holds the - pristine ladder, the verifiers and the extractors. - - `source.rs`: 222 / 135. - - `reuse.rs`: 382 / 741. - - `service_fetch.rs`: 321 / 564. - - `prestage.rs`: service-only, despite being listed in WS5. -- Server side: - - `upstream/*`: about 3,043 LOC including tests. - - `patches-shared/src/archive`: 2,041 / 1,894. - - `services/patch-package`: 3,031 / 646. - - repack overall: 6,015 / 4,976, 133 tap tests. -- Churn: - - The CLI builders are cold: npm_pack 4 commits, berry_zip 4, - pypi_wheel 7. - - The server repack is under active hardening: 31 commits, including - #22388, #23523, #25259, #26792 and #26857. -- Bug history: - - CLI builders: no packing-specific fix commit. The npm_pack (4), - berry_zip (4) and pypi_wheel (7) commits are all omnibus or feature - PRs. - - Shared machinery: registry_fetch has 11 commits (16 with `--follow`, - 15 of them fix-matching), including #175 (bundler audit, 13 bugs), - #241 (poetry) and #242 (pipenv). service_fetch has #249 (trust - hardening) and #194 (cargo fail-closed); reuse.rs came from #250. - - Server `pypi.ts`: 5 fix subjects (#21508 sdist reliability, #22724 - src-layout rescue, #22752 version spelling, #23523 artifact - integrity, #25259 bz2/xz). - -**Integrity today:** -- **Hosted mode already derives no pin.** Every value comes from the - server (`scan/hosted.rs:1282-1318`). The CLI hashes only to verify: vlt - preflight, wheel METADATA, and gem stale-cache warnings. -- **Vendored mode produces pins locally** whenever `auto` falls back: - - The fallback triggers on Pending, Unavailable, Failed, layout or - afterHash mismatch, or no client (`service_fetch.rs:170-265`). - `IntegrityMismatch` is always a hard failure. - - The CLI ignores the server's `yarnBerry10c0` (`api/client.rs:1278-1280`). - - Repair on the base branch is build-only (`commands/vendor.rs:123-126`). - - A pypi dry run always previews the local build (`pypi.rs:1807-1809`). - -**Waste the two producers cause:** -- `reuse.rs:1-12` says in its own header that it exists so "a prebuilt ↔ - local source flip between two runs (a service outage, or its recovery)" - does not rewrite the lock. -- The Auto/Service policy is hand-rolled in 7 backends (F32; 35-45 - duplicated lines each). The shared `service_archive_copy` serves only - maven and nuget. -- Every vendored reference is one POST per uuid at quota 20 each - (`client.rs:1429-1437`, F28). -- Qualifier-less pypi purls are a guaranteed service miss, downloaded in - full before being rejected (F70, F71). -- The 12 `e2e_vendor_*_build.rs` capstones (15,853 LOC, about 92 tests) and - the 58 `--vendor-source build` call sites (in 36 test files at 8ae7dc37; - the same on v5/integration) test only the local builder. - -**Unmeasured:** the real service-hit versus local-fallback rate. CLI -telemetry does not record the vendor source. `patch_vendored` is also -unclassified server-side, and its endpoint sunsets on 2026-12-31 (F22). - -### WS5 caveat answer: does depscan use CLI packing code? - -**No.** depscan has: -- no napi or FFI link to socket-patch-core; -- no crate dependency; -- no subprocess packing. - -It imports only the `@socketsecurity/socket-patch/schema` TS types -(depscan:workspaces/lib/src/socket-patch/manifest-schema.ts:9). The CLI -binary runs in depscan only in tests and tools, plus `socket-patch apply` -in the autotester image (depscan:docker/Dockerfile.autotester-worker:19-25) -and the pipeline postinstall `pnpm dlx @socketsecurity/socket-patch@4.0.0 -apply` (depscan:workspaces/pipeline/package.json:15-16). Both are -agent-mode apply, not vendoring. -`berry-cache-zip.ts` is a port of `berry_zip.rs`, not a consumer of it. -Deleting the CLI builders is therefore a CLI-only product decision. - -Two couplings are still real: -1. **depscan api-v0 e2e vendor suites 89-94** run in `auto` and silently - fall back to the local builder on a service miss. Removing the builder - weakens them without failing them. -2. **WS1 (#280) consumes CLI helpers.** It consumes `registry_fetch` and - `berry_zip` (origin/v5/ledger-free-hosted - `patch/redirect/upstream/client.rs:11,204,256-257,361-369,500-504,592`, - `upstream/vlt.rs:76`, `upstream/npm.rs:432`). Those helpers stay (see - What must stay). - -`prestage.rs` is not a local-rebuild file: it pre-extracts service -archives. - -## Design - -### Principles - -1. **One producer per (uuid, variant).** The server's verdict decides it, - never availability. The verdict is terminal; the ledger's recorded - `producer` keeps it sticky across runs. -2. **The CLI computes a pin only for `producer = local`.** Otherwise the pin - is copied from the reference and cross-checked against the verified - bytes. The two must agree, or the result is `IntegrityMismatch`. -3. **Acquire before wiring.** Every artifact in the run is acquired and - verified into the cache before any project file is written. Per-package - failures leave that package's lock untouched. -4. **Trust decisions happen in one verify step.** It never falls back to - another source on mismatch. -5. **maven and nuget keep today's artifact acquisition and wiring - byte-for-byte:** `service_archive_copy`, the local rebuild, and - `--vendor-source build`. They do take part in the batch reference POST - (step 1), which is behavior-neutral. Under contract 2 the CLI maps a - `refused` answer for a maven/nuget uuid onto the existing v1 - `build_failed`/fallback arm (or requests those uuids under contract 1), - so `service_archive_copy` behavior is unchanged. - -### When the one local build is allowed - -A class may build locally only when all three of these hold: -- (a) the server's refusal is terminal for the requested artifact (for - pypi: the uuid plus the requested filename or tags; see the TTL note - below the table); -- (b) the correct bytes depend on the user's machine; -- (c) the CLI can build deterministically from local state. - -| Class | Resolution | -|---|---| -| npm family, berry, vlt | server only; local packing deleted | -| gem (ruby platform), cargo, composer | server only; `copy_and_patch` arms deleted | -| gem platform | refused on both sides (`gem.rs:209-237`); unchanged | -| golang without go.mod | server synthesizes `module ` as proxy.golang.org does; lifts golang.ts:109-115 | -| pypi, upstream wheel exists (bare or sdist purl) | server builds the wheel variant the lock pins | -| pypi, no servable wheel (sdist-only, no tag match, bz2/xz-only) | `refused {code: pypi_no_servable_wheel, localBuild: allowed}` → `pypi_wheel.rs` from the installed dist | -| pypi, upstream file larger than the serve cap (torch, tensorflow, jaxlib, `nvidia-*` wheels) | `refused {code: artifact_too_large, localBuild: allowed}`, emitted before download from the size in the PyPI JSON → `pypi_wheel.rs` (no cap on the installed dist) | -| npm family, upstream tarball larger than the serve cap | `refused {code: artifact_too_large, localBuild: forbidden}`, emitted before download from the packument; an accepted regression (Open questions) | -| output exceeds the CLI's extraction caps | `refused {code: artifact_exceeds_client_caps, localBuild: forbidden}` (see Risks) | -| maven ext/classifier, all maven/nuget | frozen: current behavior, including `auto` fallback | - -The serve cap is `MAX_SERVABLE_ARCHIVE_BYTES` = 100 MiB -(depscan:workspaces/patches/src/services/patch-package/build.ts:37-44), and -upstream downloads are capped at 256 MiB -(depscan:workspaces/patches-shared/src/archive/repack-utils.ts:23). Today -the output-size check runs after the build, as a deterministic -`build_failed`; without the pre-download refusal, large pypi releases -would lose their only working path. - -`pypi_no_servable_wheel` is not immutable: PyPI accepts new wheels for an -existing release at any time (late cp313 or musllinux wheels are common), -and "no tag match" depends on the requester's platform. The refusal is -keyed on (uuid, requested filename or tags) and carries a TTL. Flips are -prevented by the ledger: once an artifact is recorded as -`producer = local`, later runs keep it until `--repin`. - -The retained recipe is versioned as `local:pypi-wheel/1`. It pins today's -bytes: lexicographic order, RECORD last, and fixed stamps, via -`common.rs:248` Deflated. - -`Cargo.lock:457-465` shows flate2 1.1.9 pulling both `miniz_oxide` and -`zlib-rs`, so a dependency bump could silently change the bytes. To guard -against that: -- a committed golden vector asserts the output bytes; -- the backend is pinned explicitly; -- any byte change bumps the recipe id. - -Bytes built under an old id stay reusable. Repairing one under a new CLI -fails closed with a `--repin` remedy. - -### API contract (depscan) - -**Endpoints.** -- Authenticated: `POST /v0/orgs/{slug}/patches/package` - (depscan:workspaces/api-v0/src/endpoints/orgs/patches/package.ts, quota 20 - at :293, max 500 uuids at :330). It is backed by - depscan:workspaces/app/src/patches/patch-package-references.ts. -- Anonymous: `POST /patch/package` in - depscan:workspaces/patches-api-proxy/src/server.ts:1003. It already - forwards the parsed body verbatim except for forcing `freeOnly` - (:1043-1066), and it caps bodies at 256 KiB - (`MAX_PATCH_PROXY_BODY_BYTES`, :199). - depscan:workspaces/purl-api-proxy/routes/patch.ts is a pass-through - `/patch/*` alias (including `package`) with its own 1 MB cap. -- **Body size.** A 500-uuid request with `variants` must fit the 256 KiB - cap. The CLI caps `variants` per request and chunks at fewer than 500 - uuids when variants are present. -- No new artifact routes. Bytes stay on patch.socket.dev. - -**Request (v2).** Additions are marked `+`. - -``` -{ "uuids": ["", …], // ≤ 500 - "freeOnly": false, -+ "contract": 2, -+ "variants": { "": { -+ "pypiWheelFilename": "foo-1.2.3-cp311-cp311-manylinux_2_17_x86_64.whl", -+ "pypiUpstreamSha256": ["", …], -+ "pypiWheelTags": ["cp311-cp311-manylinux_2_17_x86_64"], -+ "generation": 1 } } } // optional; repair only -``` - -`pypiWheelFilename` is the upstream file the project's lock pins (uv, pdm -and poetry list per-file hashes). `pypiUpstreamSha256` covers locks that -pin hashes with no filenames (Pipfile.lock, `requirements --hash`): the -server maps each hash to the upstream file through the PyPI JSON it -already reads, so those flavors need no installed dist and the CLI keeps -no hash-to-URL resolver. `pypiWheelTags` is the last fallback: it comes -from the installed `*.dist-info/WHEEL` when the lock pins neither, for -example requirements without hashes. `generation` lets repair request the -generation its ledger recorded. - -**Response (v2).** The endpoint returns `{ results: { : … } }` -(depscan:workspaces/api-v0/src/endpoints/orgs/patches/package.ts:147-174, -343-372). The sketch is one value of that map; additions are marked `+`. - -``` -{ + "contract": 2, - "results": { "": { - "status": "granted" | "reused" | "pending_build" | "build_failed" - | "refused" (+, v2 only) | "withdrawn" | "forbidden" | "not_found", - "url": "…" | null, // tarball URL; unchanged - "purl": "…" | null, // unchanged - + "retryAfterSeconds": 20, // pending_build only - + "failureCode": "UNSUPPORTED_ARCHIVE_FORMAT", // build_failed only; static - + "refusal": { "code": "pypi_no_servable_wheel" | "artifact_too_large" - + | "artifact_exceeds_client_caps" | "gem_platform" - + | "maven_classifier", - + "localBuild": "allowed" | "forbidden" }, // refused only - + "generation": 1, - "artifacts": [{ - "kind": "tarball" | "gem-stub-gemspec", - + "format": "npm-tgz" | "whl" | "sdist-tgz" | "sdist-zip" | "gem" - + | "crate" | "go-zip" | "composer-zip" | "jar" | "nupkg", - + "variant": "default" | "", - + "filename": "…", - "url": "…", "contentType": "…", "sizeBytes": 123, - + "recipe": "depscan-repack/npm@1", - "integrity": { "sha512": "sha512-…", "sha256": "…", "sha1": "…", - "md5": "…", "dirhashH1": "h1:…", "goModH1": "h1:…", - "yarnBerry10c0": "10c0/…" } }], // 10c0 now on the tarball - + "statement": { "payloadType": "application/vnd.in-toto+json", - + "payload": "", - + "signatures": [{ "keyid": "sp-2026-1", "sig": "" }] } - + | null, // null until backfilled - "registryOverride": { … } } } } // unchanged (hosted mode) -``` - -Schema notes: `status` and `kind` are `SEnum`s (package.ts:128-131, -148-159), so the status enum gains `refused`, emitted under contract 2 -only. Every new field is a nullable `SStruct` member. PEP 658 metadata -(F60: `pypiMetadata: { url, sha256 }` per wheel artifact, so hosted scan -stops downloading whole wheels) is a later additive v2 field and is not -in this plan. - -**Versioning rules:** -- **v1 stays schema-compatible.** With `contract` absent or equal to 1, - the response is today's except that, after step 4, `yarn-berry-zip.url` - is null (the schema already allows it, depscan:…/package.ts:124-133; no - CLI reads it, F33), and `yarnBerry10c0` is also added to the tarball's - integrity (additive; old hosted CLIs pick it up through - `integrity.clone()`): - - `kind: "tarball"` stays the authored variant, so v4 and v5.0 CLIs keep - their `find(kind == "tarball")` (`client.rs:1279-1283`) and their - `auto` fallback. - - `refused` is reported as `build_failed`. - - The `yarn-berry-zip` entry `{url: null, integrity.yarnBerry10c0}` keeps - being emitted until v1 itself sunsets. v4/v5.0 hosted scan - (`scan/hosted.rs:1290-1300`), `hosted_memory/redirect.rs:110-151` and - depscan's GitHub-app hosted PR flow - (depscan:workspaces/app/src/autopatch-pr/github-patch-pr-hosted.ts:400-426) - read the 10c0 checksum only from that entry; without it their berry - rewriter fails closed ("has no yarnBerry10c0", - depscan:workspaces/app/src/patches/registry-rewrite/yarn-berry.ts:139-143). - - `r{n}` URLs are never sent to v1 callers. For a uuid with a - generation ≥ 2, v1 is answered with the gen-1 artifact and its hashes - under the legacy URL. Old Rust and TS path parsers (vex discover, - rollback, list; depscan:workspaces/lib/src/socket-patch/patch-url.ts) - do not know the segment. -- **v2 changes:** `yarnBerry10c0` is on the tarball's integrity, and - `yarn-berry-zip` is not emitted. `r{n}` URLs appear only in contract-2 - responses. -- **Unknown fields are ignored.** The CLI response types derive - `Deserialize` without `deny_unknown_fields` (`api/types.rs`). -- **Negotiation.** The CLI sends the highest contract it supports. The - server answers `min(requested, supported)` and echoes `contract` in the - response. A breaking change needs contract 3. -- **Failure strings are static and low-cardinality**, per depscan - AGENTS.md; per-call detail goes to `logContext`. - - Deterministic statuses (`build_failed`, `refused`) never carry - `retryAfterSeconds`. - - Only `pending_build` and transient upstream failures are retryable. -- **Generations are immutable.** `generation` bumps only on an admin - regenerate, and the old generation's bytes stay served. Each generation - is a row in a per-generation table (step 7), so older URLs, hashes and - statements stay resolvable. - -**Signed statement (in-toto v1, JCS-canonical, DSSE-wrapped).** - -``` -{ "_type": "https://in-toto.io/Statement/v1", - "subject": [{ "name": "", - "digest": { "sha512": "", "sha256": "" } }], - "predicateType": "https://socket.dev/patch-artifact/v1", - "predicate": { - "uuid": "…", "purl": "…", "ecosystem": "npm", "variant": "default", - "generation": 1, "recipe": "depscan-repack/npm@1", - "upstream": { "filename": "…", "url": "…", "sha512": "sha512-…" }, - "patchRecordDigest": "sha256:", - "pins": { "sri": "sha512-…", "sha1": "…", "sha256": "…", - "yarnBerry10c0": "10c0/…", "dirhashH1": "h1:…", - "goModH1": "h1:…", "cargoCksum": "…", - "gemChecksumSha256": "…" } } } -``` - -- **DSSE binding.** `payloadType` is `application/vnd.in-toto+json`, as the - in-toto Statement v1 binding requires, so standard in-toto, sigstore - and cosign tooling can verify it. The socket-specific version lives in - `predicateType` (`https://socket.dev/patch-artifact/v1`). -- **`patchRecordDigest`.** The CLI's `.socket/manifest.json` record and - the server's DB row carry different field sets, so the digest is over - an explicit minimal projection: - `{uuid, purl, files: [{path, beforeHash, afterHash}] sorted by path}`. - The predicate schema specifies it, and a shared golden vector is used by - both the Rust verifier and the TS signer. -- **`upstream.sha512`** is the registry digest where one exists. Where - none does (GitHub-backed composer dists, legacy npm packages), it is the - server's own hash of the downloaded bytes, and beforeSha is the only - upstream anchor. - -**Signing:** -- The signer runs at build time with a GCP KMS asymmetric key (Ed25519 or - P-256, non-exportable). It is *detached*: it never touches archive - bytes. -- The in-format seam `depscan:workspaces/patches/src/repack/sign.ts` - (`defaultSign` always returns null) is deleted, as F38 recommends. - Statements are a separate build step after the write-once store. -- **Backfill.** Existing built rows get statements from their persisted - digests and columns, with no rebuild. An unsigned legacy row is never - made unvendorable. -- **Revocation.** `GET https://patch.socket.dev/.well-known/socket-patch-keys.json` - serves the key list plus a revocation list. The list is signed by an - offline root key whose public half is embedded in the CLI. -- **The CLI never trusts a key fetched at runtime.** Signing keys are - embedded (current plus next); the fetched document only *revokes* - embedded keys. - -### CLI flow (vendor, scan --mode vendored, get vendored, repair, WS2 eject) - -The flow is one shared `acquire_service_artifact` inside #283's -`VendoredBackend`, replacing the 7 hand-rolled policies (F32). maven and -nuget stay on `service_archive_copy`. - -1. **Plan.** - - Collect records from one of three places: - - `.socket/manifest.json`; - - hosted pins (WS2 eject); - - a bundle. - - Compute selection keys: for pypi, the lock's wheel filename, else - the lock's pinned sha256 hashes (Pipfile.lock, `requirements - --hash`), else the installed `WHEEL` tags. No other ecosystem needs a - key or an installed copy. -2. **Reuse, with no network.** Use `reuse::verify_committed_artifact` - (`reuse.rs:212-318`) or `reusable_committed_dir` against the ledger. - An in-sync artifact is finished here. This is a hard contract: - `vendor_rerun_no_network_e2e.rs` stays. -3. **Resolve.** Send one batch POST per 500 uuids (fewer when `variants` - would push the body past the proxy's 256 KiB cap) with `contract: 2` - plus `variants` (F28). `hosted.rs:1244` gets the same 500-chunking, because - it gets a 400 above 500 today. -4. **Decide.** The action depends on the reference answer and on the - producer recorded in the ledger: - -| Reference answer | Ledger producer | Action | -|---|---|---| -| granted / reused | any or none | acquire → verify → wire; same sha as the ledger means no lock change | -| granted, same uuid, new `generation` | service | `vendor_artifact_regenerated`: keep the committed bytes; `--repin` adopts the new ones | -| pending_build | – | poll with `retryAfterSeconds` plus jitter up to `--vendor-wait` (default 120 s interactive, 0 in CI), then `vendor_artifact_pending` (retryable) | -| refused, localBuild=allowed | – or local | local `pypi_wheel` from the installed dist; if not installed: "install, then re-run" | -| refused, localBuild=forbidden | – | `vendor_unsupported_variant` (hard) | -| build_failed | – | `vendor_prebuilt_unavailable` (hard, no local build) | -| granted, but the bytes fail layout or afterHash membership (server defect, #23144) | any | `vendor_prebuilt_defective` (hard, no local build); server-side metric | -| granted gem, stub gemspec missing or invalid (#221; pre-stub-rollout rows) | any | `vendor_prebuilt_stub_missing` / `vendor_prebuilt_stub_invalid` (hard); a server backfill (regenerate) of pre-stub rows is a prerequisite for the gem flip. Native-extension gems get no stub by design (gem.rs:922-926), so the server should answer them with a `refused` code instead | -| granted npm, berry lock, `yarnBerry10c0` null (the error-isolated berry rebuild failed, depscan build.ts:364-382) | any | `vendor_berry_checksum_unavailable` (hard) | -| network error, 5xx, timeout | local | local pypi rebuild (ledger stickiness: `producer = local` is kept); a result whose sha256 differs from the ledger fails closed with a `--repin` remedy | -| network error, 5xx, timeout | service, legacy-local, or none | `vendor_service_unavailable` (retryable); the lock is untouched | -| withdrawn / not_found | any | refuse to wire; report existing wiring for `vendor --revert` | -| any digest or signature mismatch | any | `IntegrityMismatch`, hard; never retried from another source | - -5. **Acquire** from the first source that has the bytes: - - (a) `--bundle ` (repeatable) or `SOCKET_PATCH_BUNDLE`; - - (b) the user cache `$XDG_CACHE_HOME/socket-patch/artifacts/sha512/

/`, - with the reference and statement indexed under - `index///.json`; - - (c) the service GET through the `vendor_prefetch` download window - (F28), capped by `MAX_VENDOR_PACKAGE_BYTES`. - - `--offline` stops after (b). -6. **Verify**, in this order: - - (i) the statement signature, if present; it is required for bundle - sources and, after backfill, everywhere (see Rollout); - - (ii) size, sha512 and sha256 against the reference *and* the - statement subject (`fetch_verified_archive`, - `service_fetch.rs:89-142`); - - (iii) canonical decode and afterHash membership (#249): - `tgz_bytes_match_after_hashes` (`npm_common.rs:658`), or - `zip_bytes_match_after_hashes` / `copy_matches_after_hashes` - (`common.rs`); - - (iv) go h1 via `verify_go_h1` (`registry_fetch.rs:1507`); - - (v) `patchRecordDigest` equals the digest of the projection of the - record being wired; - - (vi) berry only: `berry_cache_checksum_10c0` recomputed over the - verified tgz must equal the server value. This turns the Rust/TS - twin (F35) into a runtime tripwire. -7. **Gate.** - - By default, packages that failed are listed with their class, and - packages that verified are wired. - - `--require-all` refuses to wire anything if any required artifact is - missing. It is the plan-then-commit mode for CI that wants - all-or-nothing. - - Exit codes separate retryable (pending or unavailable) from hard - failures. -8. **Wire.** - - Directory flavors are extracted through the existing validators and - caps (`prestage.rs` pool, `registry_fetch.rs` `extract_*`/`validate_*`). - - Lock writers are unchanged; WS3 owns them. - - Pins come from the reference or statement. Local compute is allowed - only for `producer = local`. -9. **Ledger.** - - The `state.json` entry gains - `{producer, recipe, generation, statementDigest}`. - - Missing fields on old entries read as `legacy-local` or - `legacy-service`, inferred from the existing source code. - - The statement is written as `.statement.json` next to the - vendored artifact, so `vex` can attest offline. - -**Dry run.** A dry run calls the reference API only, with no GET, and -prints the real pins. It previews a local build only for -`refused/localBuild=allowed`. This fixes `pypi.rs:1807-1809` and -`npm_common.rs` "a dry run previews the local build". - -**Repair (#283).** Repair re-acquires through (a)→(b)→(c) from the ledger's -producer: -- A missing `legacy-local` artifact is re-pinned to service bytes. Only - the integrity and URL slots are spliced (the #269 vlt precedent), and - repair emits `vendor_repinned_to_service`. #283's fail-closed ledger - check (`vendored_backend/repair.rs:1-24` on origin/v5/vendor-backend) - gains this arm instead of refusing. -- Nothing else re-pins silently. `vendor --repin` does it on purpose. - -**Flags:** -- `--vendor-source` stays parseable in v5, because depscan - `99_socket-patch-cargo-modes.js:205,552` passes it. - - `auto` (the default) follows the table above. - - `service` is strict: no local bytes ever, so it also refuses - `localBuild=allowed` and the local-producer outage row. - - `build` stays valid only for maven and nuget. Anywhere else it exits 2 - with `vendor_source_build_removed` after deletion. -- New flags: `--bundle`, `--export-bundle`, `--prefetch` (fill the cache, - no wiring), `--vendor-wait`, `--require-all`, `--repin`. -- WS8 hides the rarely used ones from `-h`. - -### Per-format integrity after the change - -| Flavor | Bytes on disk | CLI verifies before write | Lock pin | Pin source | -|---|---|---|---|---| -| npm, pnpm 1–10, bun.lock/bun.lockb | served tgz verbatim | sha512 + sha256 vs reference and statement; tgz afterHash | sha512 SRI | reference; `PackedTarball::from_bytes` (`npm_pack.rs:47-60`) must agree; `bun_lock.rs:403` rehash stays verify-only | -| yarn classic | same | same | sha1 `#hash` plus integrity | reference sha1, cross-checked | -| yarn berry | same | same plus the 10c0 tripwire | `10c0/…` plus `hash=` | reference `yarnBerry10c0`; hash6 sliced from the verified sha512 | -| vlt (vendored) | tgz extracted to dir (`npm_dir` `try_service_dir`, 890-970) | tgz digests plus tree afterHash | none | — | -| pypi (service) | served wheel verbatim | sha256 + sha512; zip afterHash | wheel sha256 | reference | -| pypi (local class) | `local:pypi-wheel/1` build | afterHash of staged tree | wheel sha256 | local; ledger `producer = local` | -| gem | `.gem` → data.tar.gz dir plus served stub gemspec | digests; gem data validators; stub validity | none | — | -| cargo | `.crate` extracted; `.cargo-checksum.json` dropped; `cargo_tag` | digests | none | — | -| golang | module zip extracted; dir `replace` | digests plus `verify_go_h1` against dirhashH1 | none (no go.sum) | — | -| composer | dist zip extracted; path dist | digests (no upstream digest exists; beforeSha anchors server-side) | none | — | -| maven, nuget | unchanged | unchanged | unchanged | unchanged | - -## Offline / airgap - -- **A committed `.socket/vendor/` is the offline store.** Installs never - need Socket, and re-runs and repair of in-sync artifacts make no network - calls. Both are unchanged. -- **Cache.** The user cache is immutable and sha512-keyed, so CI can share - it across projects (actions/cache or an equivalent). -- **First vendoring or repair on an air-gapped machine uses a bundle:** - - On a connected machine, `socket-patch vendor --export-bundle ` - reads only the manifest and lockfiles and writes nothing into the - project. All pypi variants are included by default, so the bundle does - not depend on the target platform. - - On the air-gapped machine: `vendor --offline --bundle `. - - The layout doubles as a mirror an operator can host (internal HTTP, - Artifactory generic): - - ``` - /bundle.json {schema:1, createdAt, apiBase, org, cliVersion, keysetVersion} - /index/.json {record, reference (contract-2 entry), statement} - /cas/sha512// artifact bytes - /keys.json signed revocation list at export time - ``` - - Records are carried too, so WS2 eject works offline. - - Bundles carry no maven/nuget artifacts. Those frozen ecosystems keep - today's `--offline --vendor-source build` path. - - Bundle entries **must** carry a valid statement. The statement binds - the record digest and the artifact digests, so the carrier is - untrusted. -- **What is lost.** A new, non-pypi patch cannot be vendored with no - network, no cache and no bundle. Today that case builds locally - (`--offline --vendor-source build`). The pypi local class and - local-producer artifacts still work offline. This is an explicit owner - decision (Open questions). - -## Outage behavior & idempotence - -| Situation | Result | -|---|---| -| Service down; committed artifacts in sync | success, no network (reuse); unchanged | -| Service down; artifact in cache or bundle | success, fully verified | -| Service down; nothing local; producer service, legacy or none | per-package `vendor_service_unavailable` (retryable); lock untouched; remedy: retry, or `--export-bundle` elsewhere plus `--bundle` | -| Service down; producer local (pypi class) | local rebuild, same recipe id. Byte identity holds only on the same machine with the same installed dist: an sdist-only C extension compiles differently per machine. A rebuild whose sha256 differs from the ledger fails closed with a `--repin` remedy | -| `pending_build` | `--vendor-wait` polling, then retryable exit | -| Recovery storm | `retryAfterSeconds` plus client jitter plus the per-uuid breaker kept on the download step (F28) | -| Admin regenerate | new generation row, new object key; old generations stay resolvable through the per-generation table; CLI keeps committed bytes (`vendor_artifact_regenerated`), and repair of a missing artifact requests the ledger's generation | -| CDN re-encodes a body | hard `IntegrityMismatch`; `no-transform` stays on every artifact byte response (depscan:…/patch-serving/archive-response-headers.ts:11) | - -**Relation to #250 and `reuse.rs`:** -- #250 (e0246295) added reuse because the auto fallback flipped between two - producers across an outage and its recovery. -- With R1 (the verdict decides the producer) and R3 (an outage is not a - refusal), no run can pick a different producer than the ledger - recorded. Service bytes are write-once per (uuid, generation), so a - re-acquire returns identical bytes. -- `reuse.rs` stays for network-free re-runs, and its header is rewritten. - `select_prior_entry` loses its flip-hiding reason and can shrink after - deletion; that saving is unmeasured and not counted. -- A new invariant test runs every fixture capstone twice, the second time - with reuse disabled, and asserts byte-identical locks and artifacts. - -**Server side:** -- **Write-once stays** (`STORED_OBJECT_CONFLICT`, - depscan:workspaces/patches/src/services/patch-package/build.ts:425-470). -- **Regenerate never deletes in place.** All three regenerate/reset paths - fold into `resetOne()` (F39) and mint generation N+1 under a new object - key. `deleteGcsObject` is retired for referenced keys. -- **Hosted URLs become immutable too.** Hosted installer URLs gain an - optional `r{n}` segment, emitted only for generation ≥ 2 and only in - contract-2 responses. A URL without it means generation 1 forever, and - v1 callers keep getting the gen-1 artifact under that URL. The Rust path - parser learns it in the same step, with a shared redirect golden that - includes an `r{n}` case in the TS_LAGGING/RUST_IMPLEMENTED lists. -- **Per-generation storage.** `published_patches` is one row per patch - with a single `package_object_key`, `package_integrity` and - `package_size_bytes`, and the serve route resolves URL to object key - through that row - (depscan:workspaces/patches/src/services/patch-serving/serve-route.ts:125-140). - A scalar generation column cannot keep old generations served. A table - `published_patch_generations(uuid, variant, generation, object_key, - digests, size, statement)` holds one row per generation; serve-decision - resolves (uuid, generation parsed from `r{n}`, defaulting to 1) through - it. - -## Integrity, provenance & signing - -Chain of trust: -1. **Upstream digest verified server-side** - (depscan:workspaces/patches/src/repack/upstream/*: packument - integrity, PyPI sha256, crates cksum, sumdb h1, maven sha1) and - persisted as `upstreamIntegrity`. Coverage is not universal: - - composer: sha1 when Packagist supplies `dist.shasum`, else beforeSha - only (GitHub-backed dists; upstream/composer.ts:65-71); - - npm: packument integrity or shasum, else beforeSha only (legacy - packages; upstream/npm.ts:125-130). -2. **Each patched file** is anchored by beforeSha in - `substitutePatchedFiles`. -3. **The repack is built once**, written write-once and read back. The - publish-time dry run builds the same bytes only on the same host and - zlib build. F61: have the converter adopt that build instead of - rebuilding (optional). -4. **The detached statement** binds uuid → purl → upstream digest → record - digest → artifact digests → pins, signed through KMS. -5. **The CLI verifies** the signature, then the digests, then the - afterHash, then the berry tripwire (verify step 6). Only - `producer = local` pins are computed locally. - -Ride-along fixes: -- **Wheel signatures.** Strip `RECORD.jws` and `RECORD.p7s` in - `regenerateWheelRecord` - (depscan:workspaces/patches-shared/src/archive/repack-utils.ts:~1330, - F38). With a single producer, the served wheel must match what - `pypi_wheel.rs:570-585` already does. This is a behavior change and - bumps the converter version. It applies to new builds only; existing - bytes are immutable. -- **Dead signature columns.** `package_signature` and - `package_signature_kind` are always null and read only by the admin - package-job API - (depscan:workspaces/next-app/src/pages/api/admin/patches/package-job.ts:88-89,114). - They are also written by patch-sync (patch-sync/import.ts:174-175) and - queue.ts (:410-411, :733-734). Step 13b stops the writes and drops them - with a safe migration; statements live in the per-generation table. -- **Maven.** The `META-INF/*.SF` gap is recorded only (maven is frozen). - -**Provenance on disk.** The ledger holds -`producer/recipe/generation/statementDigest`, and -`.statement.json` sits next to each vendored artifact. - -**Audit.** A depscan CI golden re-runs the repackers offline over the -shared fixture corpus, split by format. The gzip bytes are -zlib-build-sensitive and differ between a dev machine and the CI runner -(depscan:workspaces/patches-shared/src/archive/repack-utils.ts:632-640), -so: -- gzip-bearing artifacts (npm tgz, pypi sdist tar.gz, the `.gem`'s - data.tar.gz, cargo `.crate`): the golden pins the sha256 of the - decompressed tar stream plus per-member afterHashes, and treats the - committed bundle bytes as opaque signed inputs, not re-derived outputs; -- STORE-zip formats (wheel, go module zip, composer zip, jar, nupkg) and - `yarnBerry10c0`: the golden asserts byte-exact digest reproduction. - -## Cache/CDN/storage cost - -**Build:** -- The default artifact costs nothing new; the converter already builds - every published row after publish. -- Added: pypi wheel variants, built lazily, keyed by - `(uuid, upstream filename)` that a client actually requested. Cost is - bounded by real demand, not by wheel-matrix width. -- Added: go no-go.mod builds, which are rare. -- Removed: the `.berry.zip` store and read-back per npm patch. The zip - rebuild stays, because it is the 10c0 source: the `berryChecksum10c0` - and `berryZip` locals (build.ts:349-350), the `rebuildBerryCacheZip` - call and the sha512 at :373-387 are kept. - -**Storage:** -- One fewer GCS object per npm patch (F33). Berry zips use STORE, so each - is likely larger than its tgz (inference, unmeasured). -- Added: the variant wheels. -- A regenerate adds a generation instead of replacing one. Old - generations are kept, because committed pins may reference them and the - server cannot know. - -**Origin I/O.** Send crc32c/md5 on the PUT and read back only on a 412 -(F34; md5 is already computed at build.ts:315/532). This removes 1–4 full -GETs per build. - -**Egress:** -- Vendoring downloads once per (project, patch), then reuses git, the - cache or a bundle. -- The CLI's eager pristine fetches from public registries disappear (F80). -- The wasted sdist downloads disappear, up to the 256 MiB cap each - (F70, F71). -- Quota drops from N×20 to ceil(N/500)×20 per run (F28). - -**CDN:** -- Keep `public, max-age=3600, no-transform` on artifact bytes. -- The per-org token in the path fragments edge keys, and revocation must - bite, so no `immutable`. -- Revisit `immutable` for generation-keyed URLs only after infra confirms - patch.socket.dev's edge-cache and auth behavior. Metadata and - go-import responses keep their current headers (F37 verification: that is - intentional). - -**Sizing.** Before step 11 (pypi variant queue), a read-only query -through the Grafana skill: count built pypi rows by selected artifact -kind, plus wheels per release from the PyPI JSON. This query is an -explicit gate on step 11. - -**Unmeasured:** variant-wheel storage, the berry.zip bytes removed, and -the egress delta. The step 5 dashboards and the pre-step-11 sizing query -produce them, and the owner reviews them before enabling -`patchPypiVariants`. - -## What gets deleted - -Deletion happens after the gate, at Phase 4. The numbers are measured by -line span at 8ae7dc37. Rows marked ~ are re-measured after #283 and #280 -land, because WS5 rewrites vendor.rs by ±318 lines. - -| Item | Files | src LOC | test LOC | -|---|---|---:|---:| -| npm_pack `pack_deterministic`, `pack_to_bytes`, `collect_regular_files`, `NPM_PACK_MTIME` (keep `from_bytes`) | `vendor/npm_pack.rs:73-177` | 105 | ~210 of 247 | -| npm_common local stage-and-pack branch | `vendor/npm_common.rs:248-396` | ~149 | in-file tests edited | -| vlt local stage branch in `stage_patch_dir` | `vendor/npm_dir.rs:~594-730` | ~137 | edited | -| registry_fetch pristine ladder: `FetchedPackage`, `fetch_and_stage`, `fetch_{npm,npm_inner,cargo,golang,composer,gem,pypi}`, `resolve_pypi_url_by_hash`, `crates_registry_base`, `stage_local_artifact(_dir)`, `fetch_npm_unverified` (**not** the WS1 keep-list) | `vendor/registry_fetch.rs` | ~700 | ~650 | -| `PackageSource` Pending/Deferred (keep the `path()` naming query) | `vendor/source.rs` | ~200 of 222 | 135 | -| cargo `copy_and_patch` | `vendor/cargo.rs` | 86 | edited | -| composer `copy_and_patch` | `vendor/composer_lock.rs` | 60 | edited | -| gem `materialise_patched_copy` | `vendor/gem.rs:1192-1339` | 148 | edited | -| golang vendored FallBack arm (`golang_local.rs` stays) | `vendor/golang.rs:~291-354` | ~64 | edited | -| Auto/Service policy arms in 7 backends, collapsed into one mapping (F32; 35-45 lines each) | 7 backends | ~220 net | edited | -| vendor.rs pristine ladder: `fetch_pristine_package`, `missing_local_rung`, `MissingRung::Fetch` | `commands/vendor.rs` | ~147 | — | -| `VendorSource::Build` outside maven/nuget, args plumbing | `vendor/mod.rs`, `args.rs` | ~30 | — | -| `berry_zip_url` plumbing (F33; re-measure on #280, which adds another `berry_zip_url: None` site at upstream/bun_lockb.rs:154) | redirect/hosted | ~3 | 41 | -| Pristine fetch-order e2e | `tests/vendor/vendor_pristine_fetch_order_e2e.rs` | — | 228 | -| **Total (CLI)** | | **~2,050** | **~1,260** | - -Rewritten, not deleted or counted: -- the 12 capstones (15,853 LOC), which move onto fixture bundles; -- the 58 `--vendor-source build` call sites (8ae7dc37), which become - `auto` against bundles (maven and nuget keep `build`); -- the fallback assertions in the in-process and covgap tests; -- `yarn_layering_tests.rs:114`; -- the pypi `in_sync_local_rebuild` tests. - -CLI additions (estimated): -- src, about 900: the acquire mapping, the cache, bundle import and - export, statement verification with the embedded keyset, ledger fields, - and the decision table. -- tests, about 900. -- Net src change: about −1,150. - -**CI.** No job is deleted, and about 0 job-minutes are saved per run. -- These keep running because they test wiring across every PM version, - which the owner keeps: - - the 58 vendored e2e legs (about 177 job-min; the 5 maven legs stay on - `build`, and the other 53 switch to fixture bundles); - - cargo-vex-matrix (18 legs); - - docker vendor jobs. -- The non-maven legs switch from local builds to fixture bundles at - similar cost. -- One test binary goes (`vendor_pristine_fetch_order_e2e`). -- depscan adds a fixture-freshness golden of about 1–2 min. -- The CI levers are F51 (≈280 job-min), F41, F52, F53 and F55 (see - v5-waste-review.md Top-10); F78, which contains F63, is a transient - saving during the v5 draft train. None is credited here. - -depscan changes: - -| Change | LOC | Source | -|---|---:|---| -| Deleted: `.berry.zip` store/read-back/serve/reset branches (build.ts:351-353 object key/size/integrity locals, :473-482 `storeSidecarObject`; serve-decision.ts:45-50, :145-157; serve-route.ts:136-137). The `rebuildBerryCacheZip` call and the sha512 at build.ts:373-387 stay | ~150 | F33 | -| Deleted: dead `sign.ts` seam plus threads (convert-patch.ts:220, run-repack-cli.ts:371) | ~60 | F38 | -| Deleted (co-landing in step 9): serve-route stream-pump duplication; admin reset paths onto `resetOne` | ~100 + ~45 | F37, F39 | -| Added (estimate): contract v2 ~150; verdict columns, per-generation table plus batched backfill and patch-sync ~220; generation-in-key, serve-decision through the generation table, and `r{n}` ~170; pypi variant queue ~450; go no-go.mod ~80; statements plus keys route plus backfill ~350; fixture exporter plus golden ~200; metrics ~60 | ~1,680 | — | - -### What must stay - -- **Verifiers:** - - `artifact_matches_integrity`, `verify_integrity` and `verify_sri` - (`registry_fetch.rs:1931-2058`); - - `go_h1_of_zip` and `verify_go_h1` (1342-1524). - `verify_sri` and `go_h1_of_zip` are private at 8ae7dc37; WS1 makes - them `pub(crate)` and calls them (origin/v5/ledger-free-hosted - `upstream/client.rs:257,367`); - - `PackedTarball::from_bytes`; - - `zip_bytes_match_after_hashes` and `copy_matches_after_hashes` - (`common.rs`); - - `tgz_bytes_match_after_hashes`. -- **`berry_zip.rs` (333 / 320), permanently.** It is a verifier - (`registry_fetch.rs:1943`, `artifact_matches_integrity`; the :1719 call - sits inside the pristine npm fetch that step 27 deletes) and the runtime - 10c0 tripwire, and WS1 calls `berry_cache_checksum_10c0` - (`upstream/npm.rs:432`). -- **The WS1 keep-list in `registry_fetch.rs`:** - - `download`, `MAX_DOWNLOAD_BYTES`, `DEFAULT_NPM_REGISTRY` (WS1 - `upstream/npm.rs:239`); - - `build_registry_client`, `RegistryClient`, `npm_registry_base`, - `npm_tarball_url`, `pypi_json_api_base`; - - `goproxy_base`, `go_match_prefix_patterns` and `go_glob_match`. - - WS1 imports all of them on origin/v5/ledger-free-hosted. Ownership - moves with F16's shared registry module if that lands. -- **Acquisition and verification plumbing:** all `extract_*`/`validate_*` - functions and the caps; `service_fetch.rs`; `prestage.rs`; - `reuse.rs` (`verify_committed_artifact`); `vendor_prefetch.rs` as a - download-only window. -- **`pypi_wheel.rs` (696 / 1,288).** It is the one local class. -- **`golang_local.rs`.** It is agent-mode redirect (`apply.rs:14`), not - vendoring. -- **Everything maven/nuget:** `local_rebuild_jar`, the nuget - `local_rebuild`, `common.rs` `rebuild_zip` and the memory repack (about - 150 src), `service_archive_copy`, and their legs. -- **depscan:** `berry-cache-zip.ts` and its test (the 10c0 source), and - the zip rebuild in build.ts. - -## Migration plan - -Prerequisites: -- **Phase 3 step 24 and Phase 4 need the owner's reversal.** After #283 - (WS5) merges, the owner reverses the WS5 caveat for non-maven/nuget - ecosystems, with the Phase 0 data in hand. Step 24 removes the local - rebuild from the default path, so it cannot land while WS5 keeps it. -- **depscan gitlink bumps** follow F79's three steps: - 1. release tip; - 2. v5/integration (#279+#281+#283), with 89-94 required not to skip; - 3. past #280, together with the GitHub-app ledger change. - - This plan's bumps come after step 3, and each one is pre-flighted with - the `socket_patch_ref` workflow input. - -Flags: -- depscan (feature_flags table): `patchPackageContractV2`, - `patchPypiVariants`, `patchArtifactStatements`, - `patchGenerationKeys`. -- CLI: `SOCKET_VENDOR_POLICY=legacy|server-primary` and - `SOCKET_PATCH_REQUIRE_STATEMENT`. - -Server steps always deploy before the CLI step that needs them. - -| # | Repo | Scope (one PR) | Gate | Rollback | Coordinates with | -|---|---|---|---|---|---| -| **Phase 0: independent wins and measurement (no policy change)** | | | | | | -| 1 | CLI | Batch reference resolution, chunked at 500 (F28); chunk `hosted.rs:1244`. maven/nuget uuids take part in the batch POST (behavior-neutral; their acquisition and wiring are unchanged) | in_process_vendor, vendor_prefetch, hosted e2e green | revert | WS4 #282 (hosted engine moves; land on whichever is first, port the other) | -| 2 | CLI | Single `acquire_service_artifact` in `VendoredBackend` (F32); warning codes kept as parameters | all vendored e2e legs byte-identical output | revert | after #283 merges | -| 3 | CLI | Drop `berry_zip_url` (F33); decide `.whl` before download (F70/F71) | unit plus pypi e2e | revert | WS3 #281 touches the same files | -| 4 | depscan | Stop storing/serving `.berry.zip` after a log check for GETs (F33), keeping the v1 `yarn-berry-zip` entry with `url: null` and adding `yarnBerry10c0` to the tarball integrity; update the v1 response snapshot; RECORD.jws/.p7s strip (F38); upload checksums (F34) | patch-package tests, installer e2e; Grafana check of `.berry.zip` requests | revert; zip columns kept until a later drop | — | -| 5 | depscan | `patch_package_reference_status_total{ecosystem,status}`, `package_status` gauges, gate counters for the future hard codes (defective afterHash/layout, missing or invalid gem stub, null berry 10c0, over-cap outputs), `/patches/package` SLO alert in workspaces/grafana-dashboards; classify `patch_vendored` (F22) | dashboards render | revert | F22 sunset 2026-12-31 | -| 6 | CLI | `patch_vendored` carries `source=reuse|cache|bundle|service|local` plus a static reason | telemetry e2e | revert | WS8 (no user-visible change) | -| **Phase 1: server contract v2 (additive)** | | | | | | -| 7 | depscan | Nullable column `package_refusal_code` (plain ADD COLUMN); table `published_patch_generations(uuid, variant, generation, object_key, digests, size, statement)` with CONCURRENTLY indexes; batched background backfill (one generation-1 row per built patch, refusal codes from build state); patch-sync import/export of the new column and table; regenerate DB types | migration on a staging copy; no long locks | columns unused, harmless | — | -| 8 | depscan | Contract v2 in patch-package-references.ts and package.ts; `refused` (SEnum, v2 only), `format`, `variant`, `generation`, `recipe`, `retryAfterSeconds`; `variants.pypiUpstreamSha256` and per-uuid `generation`; static refusals `artifact_too_large` (before download, from the upstream size) and `artifact_exceeds_client_caps` against a caps fixture shared with the CLI; github-patch-pr-hosted.ts reads 10c0 from the tarball integrity | v1 response snapshot unchanged relative to post-step-4 master; flag `patchPackageContractV2` | flag off | — | -| 9 | depscan | Generation-in-key; serve-decision resolves (uuid, generation from `r{n}`, default 1) through `published_patch_generations`; admin routes onto `resetOne` (F39); serve-route onto `serveStoredArtifact` (F37); `r{n}` URL segment, emitted in contract-2 responses only (v1 keeps gen 1 under the legacy URL), plus the lib patch-url.ts grammar | serve integration tests; regenerate-immutability test (gen-1 URL and hashes still served after gen 2); flag `patchGenerationKeys` | flag off (gen 1 only) | CLI step 10 must parse `r{n}` before any gen ≥ 2 is minted | -| 10 | CLI | Path parser accepts `r{n}`; shared redirect golden with an `r{n}` case in TS_LAGGING/RUST_IMPLEMENTED | redirect goldens (shared with depscan golden.test.ts) | revert | WS3 #281 goldens | -| 11 | depscan | pypi variant queue `published_patch_variants` (index CONCURRENTLY; claim with `UPDATE … RETURNING` plus `FOR UPDATE SKIP LOCKED`); per-variant static failure codes; `refused pypi_no_servable_wheel` keyed on (uuid, requested filename/tags) with a TTL; `refused artifact_too_large` (localBuild allowed) | pre-step-11 sizing query reviewed; real-Postgres integration harness; installer e2e for uv/pip/poetry | flag `patchPypiVariants` off | — | -| 12 | depscan | go no-go.mod synthesis matching proxy.golang.org bytes; bz2/xz sdists rejected before download (F69) | golang repack tests; hosted go e2e | revert | — | -| 13 | depscan | Statement signer (KMS) post-store, `payloadType` `application/vnd.in-toto+json`, `patchRecordDigest` over the minimal record projection with a golden vector shared with the Rust verifier; backfill statements for built rows from persisted digests; `.well-known/socket-patch-keys.json`; delete the `sign.ts` seam | real file-backed test key (a KMS double needs explicit approval); flag `patchArtifactStatements` | flag off (`statement: null`) | — | -| 13b | depscan | Stop writing `package_signature*` (queue.ts:410-411, :733-734; patch-sync/import.ts:174-175) and drop them from the admin package-job API (next-app package-job.ts:88-89,114); after one deploy, drop both columns (the drop needs no long lock); regenerate DB types | migration on a staging copy | revert before the drop | — | -| 14 | depscan | Fixture exporter: `run-repack-cli --patched-dir` over one patch per flavor → bundle layout signed with a test key, committed to socket-patch `crates/socket-patch-core/tests/fixtures/served/`; depscan golden split by format (gzip-bearing: gunzipped-tar sha256 plus per-member afterHashes, committed bytes opaque; STORE zips and 10c0: byte-exact digests); berry 10c0 vectors including sorted-vs-upstream order, CRLF, exec bits, tombstones and the Rust fail-closed cases (F35) | golden green in both repos | revert | submodule bump | -| **Phase 2: CLI consumes v2 (additive, v5.x minor)** | | | | | | -| 15 | CLI | Contract v2 client; format-before-download; `variants.pypiWheelFilename`/`pypiUpstreamSha256`/tags, chunked under the 256 KiB proxy cap; for maven/nuget uuids, v2 `refused` maps onto the existing v1 `build_failed`/fallback arm (or those uuids are requested under contract 1), so `service_archive_copy` behavior is unchanged | fixture-bundle tests; api-v0 e2e | revert | WS3 python family | -| 16 | CLI | Ledger fields `producer/recipe/generation/statementDigest`; legacy inference | ledger round-trip tests; old state.json reads | fields ignored by old code | WS6 `Ledgers` view | -| 17 | CLI | User CAS cache, `--prefetch`, `--offline` source order | offline e2e | revert | — | -| 18 | CLI | Statement verification, embedded keyset plus signed revocation list; `.statement.json`; vex reads it | tamper tests (bad sig, revoked key, digest swap) | revert | vex (WS1 discover) | -| 19 | CLI | `--export-bundle` / `--bundle` (records included; WS2 eject offline) | export → import round trip, air-gap e2e | revert | WS2 | -| 20a/b/c | CLI | Re-point capstones to fixture bundles: npm family (npm, pnpm, yarn classic/berry, bun, vlt); pypi; gem/cargo/composer/golang | every PM-version leg green; no change to maven/nuget legs | revert per family | compatibility workflows unchanged | -| 21 | CLI | Berry tripwire; pin `local:pypi-wheel/1` deflate backend plus a golden byte vector | berry e2e matrix (7 legs); pypi goldens | revert | — | -| **Phase 3: policy flip** | | | | | | -| 22 | CLI | §Decide table behind `SOCKET_VENDOR_POLICY=server-primary`; repin arms (`--repin`, repair `vendor_repinned_to_service`); dry-run parity; `--vendor-wait`; `--require-all` | reuse-disabled idempotence invariant; decision-table unit tests; regenerate test | env back to `legacy` | #283 repair.rs | -| 23 | depscan | Submodule bump with 89-94 pinned to require no skip, a strict `service` leg added, and 99 cargo-modes dropping `build` | depscan pre-flight green | revert gitlink | F79 step order | -| 24 | CLI | Flip the default to `server-primary` once the Phase 0 gate holds (30 days, per-ecosystem `pending + build_failed + fallback` < owner threshold); CLI_CONTRACT, CHANGELOG, README "Work offline" | gate data reviewed by owner; WS5 caveat reversed by owner (Open question 1) | set default back | release notes | -| 25 | CLI | `SOCKET_PATCH_REQUIRE_STATEMENT` default on, after the step 13 backfill is complete and one release has passed | zero `statement: null` in reference metrics | default off | — | -| **Phase 4: delete (one release after 24, zero `legacy` policy use in telemetry, WS5 caveat reversed)** | | | | | | -| 26 | CLI | npm-family local packers (npm_pack pack fns, npm_common/npm_dir local branches) | all npm-family legs | git revert (irreversible for users only after release) | — | -| 27 | CLI | registry_fetch ladder minus the WS1 keep-list; `source.rs`; vendor.rs ladder; `vendor_pristine_fetch_order_e2e.rs` | WS1 hosted restore tests green | git revert | #280 merged first | -| 28 | CLI | Directory-backend local arms (cargo, composer, gem, golang FallBack); collapse FallBack variants; `--vendor-source build` exits 2 outside maven/nuget | all vendored legs; cargo-vex-matrix | git revert | WS8 exit-2 convention | -| 29 | depscan | Submodule bump; api-v0 vendor suites updated | pre-flight | revert gitlink | — | -| **Phase 5 (optional)** | | | | | | -| 30 | depscan | Sandboxed sdist→wheel for pure `py3-none-any` results (autotester container infra), shrinking the pypi local class to C-extension sdist-only releases | installer e2e | flag | owner decision | - -Release boundary: -- Phases 0–3 ship in v5.x minors, except that step 24 is itself a - behavior change (the default stops building locally on outages, - `pending_build` and `build_failed`) and needs the same v5.x-vs-v6 owner - call as Phase 4. -- Phase 4 changes CLI behavior (`build` refused, `--offline` narrower). - Ship it in v5.x with one release of deprecation warnings, or in v6 - (owner call). -- Removing the `--vendor-source` flag itself is v6. - -## Risks & mitigations - -| Risk | Mitigation | -|---|---| -| First vendoring of a new patch depends on the server | committed artifacts, cache, bundles; retryable exits; SLO alert; `--vendor-wait` | -| Server defects ship to every vendored user (#23144 defective rebuilds; #24466 invalid gem stub, which #221 papered over with a local fallback) | CLI keeps afterHash and stub-validity checks, which fail closed with specific codes; depscan installer e2e plus the fixture golden; generation-in-key rolls fixes out without breaking pins | -| Hit rate is unknown | Phase 0 metrics; flip gated on 30 days per ecosystem | -| Locks that pin locally built bytes (F72 blocker 3) | reuse keeps them; re-pin only on `--repin` or when repair finds the artifact missing; one notice code | -| Air-gapped users lose ad-hoc local builds | bundles and mirror layout; pypi local class stays; owner decision | -| pypi variant fan-out | lazy, keyed by requested filename; sizing SQL first; berry.zip removal offsets storage | -| `r{n}` grammar change touches hosted URLs | only minted for gen ≥ 2 after the CLI parser ships (step 10 before step 9's flag), and only in contract-2 responses: v4/v5.0 CLIs on v1 keep getting gen 1 under the legacy URL; shared golden with an `r{n}` case | -| Server and CLI extraction caps differ: the server allows 200,000 entries and 256 MiB (depscan:…/repack-utils.ts:23,30); the CLI extractors allow 60,000 entries and 128 MiB per entry (`registry_fetch.rs:41-47`, used by `cargo.rs` extract_tgz, `golang.rs`, `common.rs`), and `patch/package.rs` is stricter still. With no local path, the server can serve an artifact the CLI must refuse | Phase 1 (step 8): the server emits static `artifact_exceeds_client_caps` when the output exceeds the CLI's published caps, checked against one caps fixture shared by both repos (or the CLI caps are raised to match) | -| Large upstream artifacts exceed the 100 MiB serve cap | `artifact_too_large` refusal before download; pypi falls back to the local class; npm family is an accepted regression (Open questions) | -| KMS or key custody | non-exportable KMS key; embedded current plus next key; signed revocation from an offline root; statements optional online until step 25 | -| Retained pypi recipe drifts on a dependency bump | golden byte vector, pinned backend, versioned recipe id | -| Old CLIs | v1 contract schema-compatible (only `yarn-berry-zip.url` becomes null; the entry and its 10c0 stay until v1 sunsets); `tarball` stays the authored variant; no `r{n}` URLs on v1 | -| depscan 89-94 masked a divergence via silent fallback | step 23 pins service mode and fails on skips | -| WS1 breakage from deletions | the WS1 keep-list is carved out; step 27 runs after #280 with its tests as the gate | -| Test doubles | capstones use committed bundles on the real import path, not a loopback service; depscan uses real Postgres, the file store and a file-backed key; any KMS or registry double needs explicit approval | - -## Design panel (record) - -Four variants were scored by three judges (integrity, ops, delivery), on a -0–10 scale: - -| Variant | Integrity | Ops | Delivery | Total | Claimed CLI src/test deleted | -|---|---:|---:|---:|---:|---| -| A: server-only plus signed bundle | **8** | 6 | 6.5 | 20.5 | 3,400 / 2,580 | -| **B: server-primary, minimal fallback (winner)** | 7 | **8** | **7.5** | **22.5** | 2,200 / 1,200 | -| C: content-addressed store plus signed manifests | 7 | 6.5 | 5.5 | 19.0 | 3,090 / 2,820 | -| D: spec-first shared builder (crate plus wasm) | 6 | 6 | 5 | 17.0 | 950 / 1,200 | - -**Why B won** (two of three lenses, highest total): -- It prevents flip-flop structurally, with sticky producers and "an outage - is not a refusal", instead of hiding it. -- It keeps the one local build that has no server substitute, so there is - no pypi airgap regression and no new sdist lock-writer arm. -- It is the smallest correct server change. -- It has an honest rollback at every phase, and it keeps `berry_zip` for - WS1. - -**Corrections applied to B:** -- The registry_fetch row now carves out the WS1 keep-list (`download`, - `goproxy_base`, `go_match_prefix_patterns`, `MAX_DOWNLOAD_BYTES`, - `npm_tarball_url`, …) and is re-measured down to about 700. -- The policy-duplication citation is F32 (220), not F31. -- `no-transform` applies to artifact bytes only (F37 verification). - -**Grafted:** -- from A: the user CAS cache; bundle export and import carrying records; - the SLO and gauges; acquire-before-wire with opt-in `--require-all`; - `.statement.json`; the fixture-bundle capstones instead of a - loopback service double; the v1 compatibility rule; the note to - re-measure after #283; -- from C: JCS canonicalization; the backfill of verdicts, generations and - statements for existing rows; the mirror layout; `r{n}` immutable - hosted URLs; upload checksums; F37 and F39 co-landing; -- from A and the integrity judge: signing promoted from optional to - planned (step 13), with a signed revocation list; -- from D: the flate2 backend caveat applied to the retained pypi recipe, - and a fixture golden as a reproducibility audit. - -**Rejected alternatives:** -- **A as a whole.** It deletes `berry_zip` and the WS1 helpers. Old rows - fail closed without statements, and there is no backfill. Its - all-or-nothing default is harsh. Eager variant fan-out is costly. It - needs a new sdist lock arm. -- **C as a whole.** It has the largest blast radius: hosted serving is - re-routed through a new CAS. It deletes `berry_zip`, which breaks WS1. - It accepts JWKS keys over TLS, which collapses trust back to TLS. A - 1-year digest-keyed shared cache plus `stale-if-error` weakens - revocation. Its automatic one-time re-pin in `vendor` is a silent - substitution path. -- **D.** Byte identity across 5 targets plus wasm is unproven, and the - fallback profile is 3–5× larger. It adds a permanent cross-repo crate - and wasm release chain. It has no signing, deletes the least code (about - 300 net src), and covers only npm and pypi. - -## Open questions for the owner - -1. Reverse the WS5 caveat (drop the local rebuild everywhere except the - pypi class, and except maven/nuget) once the Phase 0 gate passes? What - per-ecosystem thresholds? -2. Ship Phase 4 in v5.x after one deprecation release, or in v6? -3. Accept the narrower `--offline`: reuse, cache, bundle, and the pypi - local class only. Today `--offline` builds locally for every ecosystem. - Also accept that npm-family packages whose upstream tarball exceeds the - 100 MiB serve cap become unvendorable (`artifact_too_large`, no local - build)? -4. Signing: approve KMS key custody, the offline root key for revocation, - and making statements mandatory online (step 25). -5. Accept the optional `r{n}` hosted URL segment, which is a URL grammar - change shared with the depscan TS parser and the goldens. -6. pypi variant caps: is lazy on-request enough, or should pure wheels - also be built eagerly for faster first vendoring? -7. Phase 5 sandboxed sdist→wheel builds: worth the autotester-infra - dependency? -8. Telemetry: move `patch_vendored` to `/v1/orgs/{slug}/events` or extend - the 2026-12-31 sunset (F22)? The Phase 0 gate depends on it. diff --git a/docs/design/staged-rollout.md b/docs/design/staged-rollout.md deleted file mode 100644 index 09a0f5a9a..000000000 --- a/docs/design/staged-rollout.md +++ /dev/null @@ -1,1180 +0,0 @@ -# Staged patch rollout: `socket.yml` patch policy + `scan --max-new-patches` - -Status: **planned** (v5.0). Target branch `release/v5-prerelease`. -Two work items, built in parallel: **A** (policy file + filters) and -**B** (per-run limit + ordering + reporting). Section 9 specifies both. - -## 1. Goal - -Make it easy to roll Socket patches out gradually: - -1. **Repo policy in `socket.yml`.** Say which projects, ecosystems and - packages socket-patch may patch, and a severity floor. Defaults apply - when the file or the block is absent. The hard-coded repo-path filter - that exists today moves here as an overridable default. -2. **A per-run cap on new patches.** `scan` adds at most N patches to - packages that have none yet, most severe first. Repeated runs converge: - each run lands the next N. - -Non-goals: open-PR accounting (a CLI patching a working tree has no PR -state; that stays in depscan), schedules, release-age cooldowns (security -fixes are exempt from cooldowns in Dependabot and Renovate too), and -per-directory `socket.yml` files. - -## 2. What exists today (research summary) - -### 2.1 `socket.yml` v2 and its consumers - -| Parser | Where | Unknown top-level keys | Wrong type on a known key | -|---|---|---|---| -| P1 `@socketsecurity/config` 3.0.1 (archived; bundled in `socket` 1.x) | `socket-config-js/index.js:30-88` | stripped (ajv `removeAdditional: 'failing'`, `additionalProperties: false` at top level and under `githubApp`) | file rejected | -| P2 depscan copy (GitHub App, fix-PR) | `workspaces/lib/src/config-js/socket-yaml-schema.ts`, `parse-socket-yaml.ts` | stripped (same ajv options) | whole file rejected; PR check goes neutral with "error processing the socket.yml" (`diff-report-runner/index.ts:441-464`) | -| P3 socket-cli 2.x | `src/util/socket-yaml.mts` | ignored (hand-written picker) | that key dropped | -| P4 Coana | not available | unverified | reads `projectIgnorePaths` only | - -- Keys in the wild: `version` (integer; P1/P2 accept any integer, P3 - rejects anything but 2), `projectIgnorePaths`, `triggerPaths`, - `issueRules`, `githubApp.*`. Nothing mentions patches. -- **A new top-level `patches:` key breaks no parser** as long as the file - keeps `version: 2`. P1/P2 strip it, P3 ignores it. None of them will - ever see it; socket-patch is its only reader. -- Lookup: the GitHub App reads only the repo-root `socket.yml` / - `socket.yaml` at the scanned commit, and when both exist `socket.yaml` - wins (git tree order, `get-socket-repo-config.ts:96-120`). socket-cli - walks up from cwd and prefers `socket.yml`. The docs say `socket.yml` - wins. Nobody merges multiple files; there are no per-directory files. -- Glob semantics (backend): the `ignore` npm package, i.e. **gitignore - rules**, case-insensitive, tested against each manifest **file** path - (`list-files.ts:476-507`). A leading `/` or a - middle `/` anchors to the repo root, a bare name matches at any depth, a - trailing `/` matches directories only, `!` negates, last match wins, a - child of an excluded directory cannot be re-included. -- An unquoted `**` entry is a YAML error. Case-insensitivity and the - "excluded parent" rule are the two things users trip over. - -### 2.2 socket-patch v5 today - -- Selection per package: `socket_patch_core::api::ranking` - (`ranking.rs:85`): merged patches (>= 2 advisories) newest first, then - severity, then publish date, then tier/uuid. `RankKey.severity` is forced - to 0 for merged patches, so it is **not** the patch's real severity. - `severity_order` (`ranking.rs:41`) and `max_severity_order` are. -- Per-patch data: severity (max, uppercase), advisory ids, tier, optional - `publishedAt` (batch endpoint usually lacks it). No CVSS, EPSS, KEV, - reachability or direct/transitive information anywhere. -- Scan selects patches in five disk call sites plus one in the in-memory - engine: `discover_selected` (`scan/mod.rs:553`, called from `mod.rs:1999`, - `hosted.rs:1063`, `vendor_flow.rs:473`, `mod.rs:2349`), the human - agent/vendored arm (`mod.rs:2386-2402` via `get.rs:1097`), and - `hosted_memory/discover.rs:286` (`select_top_ranked`, called at - `hosted_memory/mod.rs:537`). -- Existing filters: `--ecosystems`, `--package` (`package_spec_matches`, - `mod.rs:383`), PATH globs (`path_scope.rs`), all applied after the prune - universe is captured (`mod.rs:1480`). -- Recorded state: `merge_ledger_records_for_updates` (`discovery.rs:412`, - manifest > hosted lockfile pins > vendor ledger) and `detect_updates` - (`discovery.rs:452`) with `batch_supersedes` (`ranking.rs:157`). The - in-memory engine has **no** hosted-pin discovery. -- `docs/design/configuration.md` said socket-patch never reads - `socket.yml`. This plan reverses that (section 3); the doc is updated in - the same PR. - -### 2.3 Hard-coded filtering inventory - -socket-patch (paths relative to `crates/`): - -| # | Location | What | Verdict | -|---|---|---|---| -| H1 | `socket-patch-cli/src/hosted_memory/roots.rs:56-67` `EXCLUDED_ROOT_SEGMENTS` | the in-memory engine never detects a project root under `node_modules .git .socket .yarn vendor test tests fixtures __fixtures__ testdata` | **Move** `test tests fixtures __fixtures__ testdata` to the overridable default `ignorePaths` (section 4.3), applied on disk too. Keep `node_modules .git .socket .yarn vendor` structural. | -| H2 | `socket-patch-core/src/crawlers/npm_crawler.rs:19-27` `SKIP_DIRS` (dist build coverage tmp temp `__pycache__` vendor) | npm workspace walk looking for nested `node_modules` | Stays: crawler heuristic, not selection policy | -| H3 | `socket-patch-cli/src/hosted_memory/select.rs:46,53-70` | cargo `target/` and `cargo vendor` output skipped | Stays: correctness | -| H4 | `socket-patch-cli/src/hosted_memory/roots.rs:40-53` | maven/nuget unsupported in memory | Stays: capability | -| H5 | `socket-patch-cli/src/hosted_memory/mod.rs:274` `ecosystem_allowed` | `options.ecosystems` | Stays: the in-memory `--ecosystems`; intersects with the file | -| H6 | `crawlers/python_crawler.rs:288`, dot-dir skips in `cargo_crawler.rs:373`, `go_crawler.rs:344`, `nuget_crawler.rs:236`, `ruby_crawler.rs:576` | discovery locations | Stays: crawler heuristics | -| H7 | `ruby_crawler.rs:823` BUNDLE_PATH containment | refuse config roots outside the project | Stays: **safety** | -| H8 | `scan/mod.rs:596-603`, `get.rs:1101-1107` tier filter | paid patches for free orgs | Stays: entitlement | -| H9 | `scan/mod.rs:723-762` agent partition | vendored / not-installed skips | Stays: ownership safety | -| H10 | `scan/hosted.rs:1256-1296` non-granted references | not_found, forbidden, pending_build, build_failed, withdrawn | Stays: server truth | -| H11 | `hosted.rs:1352-1402`, `hosted.rs:1448`, core rewriter refusals, vendor revert allowlists, `vlt_lock_text.rs:311` | write safety, format gates, ledger-poisoning guards | Stays: **safety** | - -No package-name, uuid or repo denylists exist anywhere in socket-patch. - -depscan (`feat/socket-patch-cli-autopatch`, PR #26860; `workspaces/app/src/autopatch-pr/cli/` unless noted): - -| # | Location | What | Verdict | -|---|---|---|---| -| D1 | `run-job.ts:94-102,293`; `next-app/.../socket-patch-cli/enqueue.ts:104` | per-org `socketPatchCliAutopatch` flag | Server (kill switch) | -| D2 | `provider/create-patch-provider.ts:189-279` | `enablePatchesAccess`, paid entitlement | Server (entitlement) | -| D3 | `lib/src/socket-patch/autopatch-job.ts:152-169` | per-job admin `config.ecosystems` allowlist, `batchSize` (lookup batch, not a patch cap) | Server; ecosystems **intersect** with `patches.ecosystems` | -| D4 | `repo-files.ts:290-513` | tree/path/size/depth caps, unsafe path drops | Server (safety) | -| D5 | `pull-request-rules.ts:473-491` | fork/default/protected heads are check-only | Server (safety) | -| D6 | `next-app/src/lib/admin/autopatch/socket-patch-cli-branches.ts:10-31` | branch-name guards | Server | -| D7 | legacy `patch-pr-worker.ts:65-109`, `github-patch-pr.ts:262-283,1598-1740`, `github-patch-pr-hosted.ts:196-486`, `compute-full-patch-set.ts:41-273` | already-applied, not-in-SBOM, unpublished, deprecated, vlt gates | Server (correctness); not policy | - -Nothing in depscan filters by repo path, package or severity, and nothing -caps patches per PR. The only repo-path policy in the whole system is H1, -and it lives in the engine. It is the one hard-coded filter that moves. - -### 2.4 Prior art (vocabulary borrowed, complexity not) - -| Tool | Limit | Counts | Order when capped | -|---|---|---|---| -| Dependabot | `open-pull-requests-limit` (5; security updates exempt) | open PRs | undocumented; shuffled | -| Renovate | `prConcurrentLimit`, `prHourlyLimit` (security fixes bypass) | open PRs / new per hour | vulnerability, `prPriority`, update type, title | -| Snyk | 5 open upgrade PRs; backlog "one PR a day, top vulnerability" | open PRs / per day | priority score | -| GitLab auto-remediation | 10 open MRs, "three vulnerabilities at a time, highest severity first", `high` threshold | open MRs + per run | severity | -| OSV-Scanner | `--apply-top=N`, `--min-severity` | per run | fixed | - -Borrowed: gitignore paths (`projectIgnorePaths`), `include`/`ignore` -pairs, `enabled`, a severity floor spelled as a minimum (`--min-severity`, -Snyk/GitLab/OSV), a per-run new-item cap (GitLab/OSV/Snyk backlog), a -fixed total order (not Dependabot's shuffle), deny-wins. - - -## 3. Trust boundary (decision) - -The rule in `CLI_CONTRACT.md` ("Repo-level files never carry endpoints, -credentials, or interlock-disablers") stays and gains its positive half: - -> A repository file may **narrow or pace** what `scan` patches. It may -> never name an endpoint or credential, pick a mode or download format, -> turn off a safety check, or make `scan` patch anything it would not -> patch with no file present. The one exception is negating the built-in -> test/fixture path ignores (4.3), which are repo policy by nature. - -Every `patches:` key only removes candidates (`enabled`, `includePaths`, -`ignorePaths`, `ecosystems`, `packages`, `ignorePackages`, `minSeverity`) -or delays them (`maxNewPatches`). No key can add a package, bypass the tier -filter, the agent partition, reference grants, containment checks or any -refusal in H7-H11. The parser has no fields for URLs, tokens, org, mode, -download mode or any `--no-*` safety switch; such keys are unknown keys and -fail validation (4.4). - -Failure direction follows from that: because the file only narrows, an -unreadable or invalid policy must not mean "no policy". It fails closed. -And because a policy can hide security fixes, what it hides is always -reported (4.7, 7.3), never silent. - -## 4. `socket.yml` grammar (work item A) - -### 4.1 Keys - -```yaml -version: 2 # required for socket-patch to honor `patches` -projectIgnorePaths: # existing scanner key; socket-patch honors it too - - "crates/*/tests/fixtures/**" -patches: # new; every key optional - enabled: true # bool. Default true. false = report only. - includePaths: ["/services/payments/"] # gitignore list. Absent = every project. - ignorePaths: ["/legacy/"] # gitignore list, evaluated after the defaults. Default []. - ecosystems: [npm, pypi] # allowlist of --ecosystems names. Absent = all. - packages: ["pkg:npm/lodash"] # allowlist of --package specs. Absent = all. - ignorePackages: ["pkg:npm/left-pad"] # denylist of --package specs. Default []. - minSeverity: high # critical|high|medium|moderate|low. Absent = no floor. - maxNewPatches: 5 # integer 0..=4294967295. Absent = unlimited. 0 = upgrades only. -``` - -- camelCase, like every existing socket.yml key. -- Ecosystem names are any `Ecosystem::cli_name()` (`npm pypi cargo gem - golang maven composer nuget deno`), case-insensitive, valid whatever the - build supports; an unsupported ecosystem simply matches nothing. -- Package specs use exactly the `--package` grammar and matcher - (`package_spec_matches`, moved from the cli crate to core by A): a name - (full or last segment, case-insensitive) or a purl with or without a - version; qualifiers ignored. A bare name matches across ecosystems and - by last segment (`core` matches `@babel/core`), so the docs recommend - purls in `packages`/`ignorePackages`. Invalid spec: empty, or `pkg:` - without a type and name. -- `moderate` is an alias of `medium` everywhere (file, flag, env, napi). -- An empty allowlist (`includePaths: []`, `ecosystems: []`, - `packages: []`) is an error ("use `enabled: false`"), never "all". -- Deny wins: `ignorePackages` beats `packages`, ignore paths beat - `includePaths`. - -### 4.2 Precedence against flags and env - -| Setting | Rule | -|---|---| -| List filters (paths vs PATH args; `ecosystems` vs `--ecosystems`; `packages`/`ignorePackages` vs `--package`) | **intersect**: flags narrow further, never widen | -| `minSeverity` | `--min-severity ` > `SOCKET_MIN_SEVERITY` > file > no floor | -| `maxNewPatches` | `--max-new-patches ` > `SOCKET_MAX_NEW_PATCHES` > file > unlimited | -| whole file | `--no-socket-yml` / `SOCKET_NO_SOCKET_YML` (bool, the contract's spellings) skips the file; built-in default path ignores still apply | - -Scalars follow the contract's CLI > env > default order, with the file as -the layer above the default. The person running the CLI is trusted; the -file is the repo's default. Every new flag has an env binding. An empty env -value is unset (repo-wide rule); a malformed flag or env value is a usage -error (exit 2). depscan adds its own server ceiling (7.1). - -### 4.3 Paths - -- **Subject: marker files.** The backend tests `projectIgnorePaths` - against manifest file paths, so socket-patch does the same for every - path list. A project root's **markers** are the lockfile/manifest files - in its directory that the engine reads for it (disk: the root's - lockfiles per the formats registry, plus its manifest; memory: - `hosted_memory/roots.rs` marker files). Paths are repo-relative with `/` - separators, e.g. `services/api/package-lock.json`, `package-lock.json` - for the repo-root project. - - A root is **ignored** iff **every** marker is ignored. - - With `includePaths` set, a root is **included** iff **any** marker - matches `includePaths`. - - Admitted iff included and not ignored. - This makes `/package-lock.json`, `**/yarn.lock`, `examples/**` and - `crates/x/fixtures/**` mean what they mean to the scanner, and needs no - special form for the repo-root project (target only it with - `includePaths: ["/*", "!/*/"]`). -- **Semantics: npm `ignore` exactly.** gitignore rules, case-insensitive, - anchored at the repo root: a leading or middle `/` anchors, a bare name - matches at any depth, a trailing `/` matches directories only, `!` - negates, last match wins. Evaluation walks **top-down**: for - `a/b/c.lock`, test `a/`, then `a/b/`, then the file; the first ignored - ancestor decides and a negation cannot re-include anything under it - (`fixtures/` + `!/a/fixtures/keep/` leaves `keep` ignored, as in the - backend). Do not use `ignore::gitignore`'s `matched_path_or_any_parents` - as-is: it walks bottom-up and would re-include. Implement the walk over - `Gitignore::matched(path, is_dir)`. `includePaths` uses the same walk - with "matched" in place of "ignored". -- A golden fixture of (patterns, path, expected) generated from the npm - `ignore` package is checked into the tests; the Rust matcher must agree - on all of it. -- **Pattern hygiene.** Reject (4.4) patterns that contain a `..` segment, a - drive letter, NUL, or exceed 1024 bytes. Backslash is gitignore's escape - character, not a separator (documented). -- **Evaluation order** of the ignore lists (one combined list, last match - wins within a path, top-down across ancestors): - 1. built-in defaults: `test/ tests/ fixtures/ __fixtures__/ testdata/` - 2. `projectIgnorePaths` - 3. `patches.ignorePaths` - - Re-include a default with a negation: `ignorePaths: ["!/e2e/tests/"]`. - Adding an unrelated ignore never re-enables fixtures. The defaults are - now case-insensitive (`Test/` too), unlike H1. The backend's own - scanner defaults (`coverage`, `bower_components`, …) are not mirrored: - those are not dependency roots socket-patch would find. -- **Defaults apply to discovered roots only.** Step 1 never applies to a - root the user named explicitly: - - | Mode / entry point | Explicit roots | Discovered roots | - |---|---|---| - | disk hosted/vendored | `--cwd` with no PATH; a literal (non-glob) PATH | PATH-glob matches (`run_project_dirs` carries the flag per directory) | - | disk agent | `--cwd` (its only project; agent PATHs are package globs, not roots) | none | - | in-memory | roots given in `projectRoots` | roots found by detection | - - Steps 2-3 and `includePaths` apply to every root. -- **Structural excludes** (`node_modules .git .socket .yarn vendor`) stay - hard-coded and cannot be negated. -- **Granularity.** A workspace member that shares the root lockfile is part - of the root project; exclude it with `ignorePackages`, not paths. -- **Outside the repo.** Roots are canonicalized; a PATH that resolves - outside the repo root (4.5) is a usage error (exit 2). One policy per - invocation. - -### 4.4 Validation (fail closed) - -socket-patch validates `version`, `projectIgnorePaths` and `patches`, and -checks top-level key names for case variants of `patches`. It does not -validate any other key. - -Checks run in this order: file access, encoding, YAML, top-level shape, -case-variant check, version gate, keys. - -| Situation | Behavior | -|---|---| -| No file; empty or comment-only file | no file: defaults | -| Not a regular file after resolving (directory, FIFO, device), resolves outside the repo root, larger than 64 KiB (read at most 64 KiB + 1 from the opened handle; metadata from the same handle) | **error** | -| Invalid UTF-8, UTF-16, NUL bytes (a UTF-8 BOM is stripped; CRLF is fine) | **error** | -| YAML syntax error, duplicate key, top level not a mapping, nesting deeper than 32 | **error** | -| An anchor, alias or merge key (`<<`) inside `patches` or `projectIgnorePaths` | **error** (bounds expansion; nobody needs them here) | -| Top-level key equal to `patch` or `patches` ignoring case but not exactly `patches` | **error**: a misspelled block must not mean "no policy" | -| `patches` present and `version` is not 2 (integer 2 or string `"2"`, as ajv coerces), including missing | **error** ("patches requires version: 2") | -| `patches: null` or `patches: {}` | defaults | -| Unknown key under `patches` | **error**, with a did-you-mean hint (edit distance <= 2) and "a newer socket-patch may support it; upgrade or remove it" | -| Wrong type (no coercion: `"false"` is not a bool; YAML 1.2, so `no` is a string), unknown severity, `maxNewPatches` not an integer in range, empty allowlist, invalid pattern or spec, a list over 1000 entries, an entry over 1024 bytes | **error** naming the key path (`patches.minSeverity`) | -| `projectIgnorePaths` with a `patches` block present: a string is coerced to a one-element list (as ajv does); anything else not a list of strings is an **error** | | -| `projectIgnorePaths` with **no** `patches` block: same coercion; otherwise warning `socket_yml_ignored_value` and the key is ignored | repos that never opted in do not start failing on a scanner key | -| No `patches` block, any `version` | `projectIgnorePaths` honored whatever the version, as the backend (P2) does | -| Both `socket.yml` and `socket.yaml` at the root | validate both (either invalid is an error). If their `projectIgnorePaths` and `patches` are equal as parsed values (order-sensitive), use `socket.yml`; otherwise **error** `socket_yml_ambiguous`. The existing consumers disagree on which file wins, so we refuse to pick. | -| Only a case variant exists (`Socket.yml`) | not read (the name must match a directory entry exactly, via `read_dir`, so case-insensitive disks behave like the memory tree); warning `socket_yml_name_case` | - -**Error behavior.** Before any write, `scan` fails with exit **1** and -`errorCode: socket_yml_invalid` (or `socket_yml_ambiguous`). The message -names the file, the key path and the remedy (fix the file, or -`--no-socket-yml`). Exit 1, not 2: it is a bad input file, like an invalid -manifest. Scan's JSON is still the legacy shape (not the unified envelope): -the error output is scan's existing error object `{"status": "error", -"error": ""}` plus an additive `"errorCode"`; no `policy` or -`rollout` block is emitted on error. - -Every string copied from the file into output (patterns, specs, key names) -is truncated to 200 characters with control characters stripped; depscan -additionally renders them as escaped code spans (7.3). - -Keys are only ever added in minor releases and never change meaning. An -older pinned CLI fails on a newer key by design, and the error says so. - -### 4.5 Lookup - -1. Canonicalize `--cwd`. Repo root := the nearest ancestor (inclusive) - containing `.git` (a directory, or a file for worktrees and submodules), - not walking past any directory in `GIT_CEILING_DIRECTORIES`, and, on - Unix, only if `.git` is owned by the current user or root (git's - safe.directory spirit; otherwise warning `socket_yml_repo_untrusted` - and the walk stops). With no qualifying `.git`, repo root := `--cwd`. - Never the home directory unless `--cwd` is it; never above `--cwd` - without a `.git`. -2. Read `/socket.yml` and `/socket.yaml` only. - Nested files are never read (one file per repo, as in the GitHub App). - A symlinked socket.yml is followed only if it resolves to a regular - file inside the repo root. -3. In memory, the repo root is the tree root; the caller supplies the - file's content to path selection and to the session (7.2). A socket.yml the tree lists but the engine never - receives, or receives only as present-without-content (symlink, - oversize, LFS pointer, binary), is `socket_yml_invalid`, never absent. -4. `--global` / `--global-prefix` scans have no repo and ignore the file. - -### 4.6 Commands - -| Command | Policy | -|---|---| -| `scan` (hosted, vendored, agent; wet and `--dry-run`), `hosted-bundle`, the napi engine | honor filters and limit | -| `get` | explicit intent: ignores filters and limit; warns `policy_bypassed` when the target would have been filtered; never fails on the policy (an invalid file just skips the warning) | -| `apply`, `list`, `vex`, `rollback`, `remove`, `repair`, `vendor` (eject/revert) | ignore it: they report, attest or undo existing state | - -**Narrowing never removes.** The policy runs after the prune universe is -captured (`mod.rs:1480`), so `--prune` still judges the full crawl. A -package that already has a recorded patch but is now excluded by paths, -ecosystems, packages or `enabled: false` is **retained**: not passed to the -hosted rewriters, vendor engine or agent apply; not upgraded; not taken -over; left byte-identical. It is reported under `policy.retained[]` with -`upgradeAvailable`. Removing a patch is only ever `rollback`/`remove`, or -the dependency leaving the lockfile. - -**Severity floor.** One data source: the by-package records the selector -already fetches (`fetch_patch_details` on disk, the provider's by-package -lookup in memory), severity = `max_severity_order` over the patch's -`vulnerabilities`, never `RankKey.severity` (forced to 0 for merged -patches) and never the batch list. The floor restricts which candidates -may **win** per-package ranking; a lower-ranked patch above the floor can -still win. With a floor set, unknown severity is filtered (fail closed; -note `minSeverity: low` therefore drops unknown-severity patches, which the -recipes say). Supersession of a recorded patch is judged against the -**unfiltered** offer list (5.1): the floor never turns a recorded patch -into "no longer offered". A recorded package with no candidate above the -floor keeps its recorded patch (ALREADY). - -`enabled: false`: discovery and the table still run; nothing is written; -every candidate is reported filtered with `policy_disabled`; warning -`patches_disabled`; exit 0. Upgrades are frozen too. - -### 4.7 JSON (`policy` block, owned by A) - -Additive top-level key on every successful `scan --json` result (MINOR), -always present. Policy warnings go to scan's top-level `warnings[]`. - -```json -"policy": { - "source": "file", - "path": "socket.yml", - "sha256": "…", - "enabled": true, - "minSeverity": {"value": "high", "source": "file"}, - "counts": {"filtered": 3, "retained": 1}, - "filtered": [ - {"purl": "pkg:npm/qs@6.5.2", "uuid": null, "project": "services/legacy", - "reason": "policy_path_excluded", "detail": "/legacy/ (patches.ignorePaths)"} - ], - "retained": [ - {"purl": "pkg:npm/lodash@4.17.20", "project": "", "recordedUuid": "…", - "reason": "policy_package_ignored", "upgradeAvailable": true} - ] -} -``` - -| `source` | When | `path` / `sha256` | -|---|---|---| -| `none` | no file, empty file, file ignored (`--global`), or only a case variant | null | -| `file` | a root file was read (with or without a `patches` block) | the file used (`socket.yml` when both are equal) / its bytes' hash | -| `bypassed` | `--no-socket-yml` / `SOCKET_NO_SOCKET_YML` | null | - -- `project` is the repo-relative root directory; the repo root is `""` - (the memory engine's spelling) everywhere. -- `minSeverity.source` is `flag|env|file|default`; `value` null = no floor. -- `uuid` is null when the package was filtered before any patch lookup - (path, ecosystem, package reasons). A root filtered as a whole is one - entry with `purl: null`. -- `counts.filtered` counts entries of `filtered[]`; `counts.retained` - counts entries of `retained[]`. -- Reason codes (stable): `policy_disabled`, `policy_path_excluded`, - `policy_path_not_included`, `policy_ecosystem`, - `policy_package_not_listed`, `policy_package_ignored`, `policy_severity` - (detail `unknown < high` or `medium < high`). -- Human output: one line, e.g. `Policy (socket.yml): 3 skipped by filters, - 1 patched package held.` Filtered critical/high candidates are always - named on the human path (a policy must not silently hide them); - `--verbose` lists everything. - -## 5. Per-run limit (work item B) - -### 5.1 Classification - -**Recorded view.** Always the merged view, in every mode and both engines: -`merge_ledger_records_for_updates` (manifest > hosted lockfile pins > -vendor ledger), scoped to the lockfiles and state files of the project -root being written. The in-memory engine reads the same three stores from -the tree (`.socket/manifest.json`, `.socket/vendor/state.json`, hosted -pins discovered from the in-memory lockfiles; new, B). When the lockfiles -of one root pin a purl to different uuids, the recorded uuid is the -selected uuid if it is among them, else the smallest (today's rule). - -**Supersession** uses the by-package records (the same data as selection -and the severity floor), with the `batch_supersedes` rungs applied to -them: merged over unmerged, higher severity between unmerged, a real, -strictly later publish date. It is judged against the **unfiltered** offer -list. B adds the by-package twin of `batch_supersedes` in `ranking.rs`; -`detect_updates` and scan's `updates[]` switch to it so classification, -selection and reporting can never disagree. - -After filtering and per-package selection, each selected `(project root, -purl)` row is: - -| Class | Rule | Counts toward the cap | Writer receives | -|---|---|---|---| -| ALREADY | recorded uuid == selected uuid, or the selection does not supersede the recorded uuid | no | the **recorded** uuid (re-confirmed idempotently) | -| UPGRADE | the selection supersedes the recorded uuid, or the recorded uuid is no longer offered at all (unfiltered) | no | the selected uuid | -| NEW | nothing recorded for this base purl in this project root | **yes** | the selected uuid, if admitted | -| ALREADY (kept) | recorded, offers exist in `Offers.unfiltered` but none survive the floor | no | the recorded uuid (counted in `counts.already`) | - -- NEW is per project root. Widening `includePaths` makes piloted packages - NEW in the added roots, so they go through the cap again. -- UPGRADEs are exempt (decision): rollout risk is about whether a package - runs patched code at all, and an upgrade fixes more in an already-patched - package. `enabled: false` freezes everything; `maxNewPatches: 0` freezes - new packages only. -- **Known limit: version bumps.** When a dependency moves to a new version - its hosted pin goes with the old lockfile entry, so the new version is - NEW and goes through the cap. (Hosted state cannot tell a bump from a new - package.) Documented. -- **Qualifier twins** (wheel/sdist, gem platforms) share a base purl. If - one twin lands and another was ineligible, the next run sees the base - purl as recorded and the late twin lands as ALREADY/UPGRADE, uncapped. - Documented; it is one package. - -### 5.2 Eligibility, budget and ordering - -- **Eligibility is decided by the planning pass**, the same pass - `--dry-run` runs, before any budget is spent. A NEW row is eligible only - if every check that can be decided without writing passes: - - tier filter; - - agent partition (vendored / not installed); - - vendored preflight; - - hosted reference grant `granted`, with a usable purl and url; - - vlt artifact preflight; - - symlink refusals; - - rewriter planning shows at least one lockfile edit that would pin it - (no refusal, entry found). - - Ineligible rows keep their existing skip reasons and never hold a slot, - so a patch that cannot land can never stall the rollout. -- **One fetch strategy.** References are requested for every eligible-so-far - candidate (NEW, UPGRADE and ALREADY) in the run's normal batches, before - budgeting; never lazily in rank order. A reference or lookup failure that - affects only rows that end up deferred never fails the run or the root; - it becomes warning `rollout_reference_failed`. -- **Incomplete data.** With a finite cap, if any batch, detail or reference - lookup failed for a package that could have been NEW, no NEW row is - admitted this run (all NEW rows deferred) and warning - `rollout_incomplete_lookup` is emitted. Otherwise a failure would let - lower-ranked patches take the missing ones' slots. ALREADY and UPGRADE - rows proceed as today. -- **Unit:** a distinct **base purl** (ecosystem + name + version, - qualifiers stripped, via one shared core function `canonical_base_purl`) - among eligible NEW rows. Admitting a base purl admits all of its eligible - NEW rows in every root of the invocation; it costs 1 slot. -- **Scope of the budget:** - - in-memory engine: one budget across all roots (collect, plan, apply); - - disk: one budget per invocation. `run_project_dirs` visits - directories in sorted order and passes the **remaining** budget to - each, together with the set of base purls already admitted (a base - purl admitted in an earlier directory is admitted free in later ones); - each directory spends the budget in rank order. `scan --json` accepts one - directory, so a CI job per directory gets N per directory. Documented. -- **Order** (ascending; total; no time-dependent keys): - 1. in-flight first (in-memory option `inFlightPatches` only, matched by - base purl; absent on the CLI) - 2. severity of the selected patch (`max_severity_order`: critical, high, - medium, low, unknown) - 3. advisory count, descending (merged patches first within a severity) - 4. ecosystem `cli_name`, ascending - 5. canonical base purl, ascending bytewise - 6. smallest selected uuid across the base purl's rows, ascending - - A base purl in several roots uses the minimum key over its rows. - `publishedAt` is not a key: it would reorder the queue whenever a date is - missing. Per-package ranking (which patch a package gets) still uses - `publishedAt` as today; this order only decides which packages go first. -- **Write failures** after admission (I/O at commit time) consume budget - and are reported as failures. No backfill within a run, so `--dry-run` - predicts the wet run exactly. -- **`maxNewPatches: 0`** admits no NEW rows; ALREADY and UPGRADE proceed. -- Everything eligible and NEW beyond the budget is **deferred**: not - written, not downloaded, not vendored, reported with its rank. - -### 5.3 Convergence and determinism - -- Same inputs, same plan, same bytes. The limit is stateless: run k lands - the top N; on run k+1 they are ALREADY and the next N land. M waiting - patches take **at most** ceil(M/N) committed runs, absent new or - ineligible patches. -- A newly published or re-scored higher-severity patch moves ahead of the - queue. That is intended ("most critical first") and visible, because - every deferred entry carries its rank and severity. -- Low-severity patches can wait indefinitely while higher ones keep - arriving. Documented; it is the point of severity ordering. -- **CI that does not commit** the scan's result never advances recorded - state, so a cap there means "only the top N, every run". The recipes - say: commit the lockfile changes (or use a PR bot), or set no cap in - non-committing jobs. -- `pending_build` references are transient: a row can be ineligible one - run and eligible the next. The plan is still a function of the inputs. -- `--dry-run` fetches reference grants like a wet run (it must, to decide - eligibility), so it has the same server-side effects a dry run has - today. - -### 5.4 Modes - -| Mode | ALREADY / UPGRADE surface | Deferred rows | -|---|---|---| -| hosted (disk) | re-confirmed / rewritten, as today | never rewritten; mirrored into `redirect.skipped[]` with reason `rollout_deferred` | -| vendored | `already_vendored` / `would_revendor` | never downloaded or vendored | -| agent | `skipped` / `updated` | never downloaded; not in `apply.patches[]` | -| in-memory (napi, hosted-bundle) | as hosted | in `ProjectResult.deferred[]` and `skipped[]` with `rollout_deferred` | - -Recorded state is the merged view (5.1) in every row. A takeover of an -existing vendored or hosted entry counts as recorded, not NEW. `--dry-run` -makes exactly the same decisions. - -### 5.5 JSON (`rollout` block, owned by B) - -Additive top-level key on every successful `scan --json` result (MINOR), -always present: - -```json -"rollout": { - "maxNewPatches": {"value": 5, "source": "file"}, - "counts": {"new": 5, "deferred": 9, "upgrade": 1, "already": 12}, - "deferred": [ - {"purl": "pkg:npm/minimist@1.2.5", "uuids": ["…"], "severity": "critical", - "advisoryCount": 1, "projects": ["services/api", "services/web"], "rank": 6} - ] -} -``` - -- `maxNewPatches.value` null = unlimited; `source` is - `flag|env|file|default|cap`. -- `counts.new` and `counts.deferred` count base purls (admitted this run, - or would be under `--dry-run`; deferred). `counts.upgrade` and - `counts.already` count `(project, purl)` rows. -- `deferred[]` is in rank order; `purl` is the base purl; `uuids` lists - the distinct selected uuids across its rows and qualifier twins; `rank` - is 1-based among **eligible** NEW base purls. Ineligible rows are not - ranked; they appear under their existing skip reasons. -- Human output (after the mode's summary, then the Next-steps renderer): - - ``` - Rollout: 5 of 14 new patches applied (maxNewPatches=5 from socket.yml); 1 upgrade, 12 already applied. - Next steps: - 9 new patches deferred; commit these changes and run scan again to apply the next 5. - Next up: minimist@1.2.5 (critical), qs@6.5.2 (high), … - ``` -- Exit code unchanged (0) when patches are deferred or filtered. -- `jq` recipe for CI: `jq '.rollout.counts.deferred'`. - -## 6. Rollout recipes - -```yaml -# R1 Canary: one new patch per run -version: 2 -patches: - maxNewPatches: 1 -``` - -```yaml -# R2 Critical first: widen by editing one line -version: 2 -patches: - minSeverity: critical # later: high, then low, then remove the key - maxNewPatches: 5 # (low still skips patches whose severity is unknown) -``` - -```yaml -# R3 One directory first (monorepo) -version: 2 -patches: - includePaths: - - "/services/payments/" - # add "/services/checkout/" next sprint - maxNewPatches: 5 -``` - -```yaml -# R4 One ecosystem, hold one package -version: 2 -patches: - ecosystems: [npm] - ignorePackages: ["pkg:npm/left-pad"] -``` - -```yaml -# R5 Weekly drip with the depscan autopatch PR -version: 2 -patches: - maxNewPatches: 5 # the PR keeps the same 5 until merged, then the next 5 -``` - -```yaml -# R6 Pause -version: 2 -patches: - enabled: false # report only; existing patches stay in place -# or keep upgrades flowing but add nothing new: -# maxNewPatches: 0 -``` - -A cap only advances when the scan's changes are committed (or merged by a -PR bot). In a CI job that scans without committing, set no cap. - -One-off overrides from the command line: `socket-patch scan ---max-new-patches none` (drain the queue this run), `--min-severity none`, -`--no-socket-yml` (ignore the file entirely). - -## 7. depscan autopatch service - -### 7.1 Behavior with the new engine - -- `repo` jobs rebuild one commit from the base SHA each run. With - `maxNewPatches: 5`, "recorded" means recorded on the **base** branch, so - every rebuild proposes the same top 5 until the PR merges, then the next - 5. `inFlightPatches` (the base purls already in the open PR) keeps a - reviewed patch from being displaced by a newly published one mid-review. -- **Policy source.** Both job kinds read socket.yml from the **base** SHA: - the reviewed, merged policy. A pull request cannot loosen the policy - that judges its own check (for example by adding `ignorePackages` for - the vulnerable dependency it introduces). If the PR head changes - `patches` or `projectIgnorePaths`, the check run says so and lists what - the head's policy would additionally filter. -- `pull_request` jobs honor the filters and pass `maxNewPatches: "none"` - and **no** `maxNewPatchesCap`: deferring there would leave the check - permanently showing work. -- Effective limit for `repo` jobs = min(repo value, `maxNewPatchesCap`). - The server can tighten, never loosen; the cap applies to every value - including `"none"`. Org-level kill switches, entitlement and safety - (D1-D6) always win. - -### 7.2 Engine API changes (napi `HostedScanOptions` / result, and the `hosted-bundle` harness) - -| Owner | Change | -|---|---| -| A | Two-phase selection so the memory engine applies the same path policy as disk. `selectHostedScanPaths` gains an option `policyFiles?: Array<{path: string, text: string} \| {path: string, missing: true}>`, one entry per root `socket.yml` / `socket.yaml` the listing contains (the both-files rule of 4.4 applies): the caller fetches those root blobs first (they are root files, known from the tree listing) and passes the content. The selector parses it with the same loader and applies the **full** path policy (defaults, `projectIgnorePaths`, `patches` lists, negations) when choosing which files to fetch, so an `ignorePaths` negation re-includes a default-ignored tree in memory exactly as on disk. If the listing has a root policy file with no matching entry, or an entry is `missing: true`, or the text is invalid, the selector returns `policyError` (never "no policy"). The session re-parses the same text and fails `socket_yml_invalid` if the policy content that arrives differs (sha256) from what the selector saw | -| A | the session applies the full policy to detected roots **before** the `max_projects` check (`hosted_memory/mod.rs:377`) | -| A | options `noSocketYml?: boolean`, `minSeverity?: "critical"\|"high"\|"medium"\|"moderate"\|"low"\|"none"` | -| A | result: session-level `policy` block (4.7) and `policyError?: {code, detail}`; on error no root is processed and no files change; `skipped[].reason` gains the `policy_*` codes | -| B | options `maxNewPatches?: number \| "none"`, `maxNewPatchesCap?: number`, `inFlightPatches?: string[]` (base purls) | -| B | result: session-level `rollout` block (5.5); `ProjectResult.deferred[]`; `skipped[]` rows with `rollout_deferred` | -| B | hosted-pin discovery over the in-memory lockfiles and reading `.socket/manifest.json` / `.socket/vendor/state.json` from the tree, for the merged recorded view. A finite cap must never ship in the engine without it: every merged pin would look NEW and the rollout would stall at N. | -| B | restructure the per-root loop around `hosted_memory/mod.rs:537` into collect all roots → plan once → apply, so the budget is run-wide | - -`hosted-bundle` rejects unknown fields, so each owner adds its fields there -too. - -### 7.3 depscan follow-up (after A and B merge; separate PR in depscan) - -1. Bump the socket-patch submodule and rebuild the addon. -2. Fetch the root socket.yml / socket.yaml blob from the **base** SHA - for both job kinds **before** calling `selectHostedScanPaths`, and - pass them as `policyFiles` (7.2); stream the same content to the session. - Never let the file be dropped by the size/path caps silently: a - missing or oversize policy blob is passed as `missing: true`, which the - engine turns into `policyError`. -3. Pass `inFlightPatches` (base purls in the open patch-all PR); for - `pull_request` jobs pass `maxNewPatches: "none"` and no cap. -4. New job outcome `policy_invalid` (from `policyError`): leave the - existing PR untouched, surface the error on the admin page and in the - check-run text. -5. PR body and check run: a "Deferred (next batch)" table with severity - and rank; `policy.filtered`/`retained` counts, naming every critical or - high candidate the policy suppressed; a note when the PR head changes - the policy. Render every file-derived string as an escaped code span, - truncated. -6. Stats: `patchesDeferred`, `patchesFiltered`. -7. Optional server cap per org (future setting) passed as - `maxNewPatchesCap`; keep passing the admin `config.ecosystems` (D3) as - `ecosystems`, which intersects with the file. -8. Do **not** add `patches` with strict types to the ajv schema in - `socket-yaml-schema.ts`: a typo there rejects the whole file and turns - PR checks neutral. If wanted for docs, add a permissive `{type: object}`. -9. Docs repo: a `patches` section on the socket.yml page; fix the two - stale statements found in research (which file wins when both exist; - v1 files are rejected by the GitHub App). - -A closed or rejected rolling PR re-proposes the same patches next run; -`ignorePackages` is the documented way to decline one. - -## 8. Decisions log - -| # | Decision | Why | -|---|---|---| -| 1 | Top-level `patches:` in socket.yml v2; no `version: 3` | breaks no parser (P1/P2 strip, P3 ignores); P3 rejects any version but 2 | -| 2 | socket-patch reads socket.yml (reverses configuration.md) | owner request; policy that only narrows fits the trust boundary | -| 3 | Keys `enabled includePaths ignorePaths ecosystems packages ignorePackages minSeverity maxNewPatches` | include/ignore pairs mirror existing keys; `packages` covers single-package pilots; `maxNewPatches` says it counts new patches only | -| 4 | Paths match marker **files**, npm-`ignore` semantics, top-down, case-insensitive; golden parity fixture | identical meaning to `projectIgnorePaths` in the backend; no root special form | -| 5 | socket-patch also honors `projectIgnorePaths` (leniently when there is no `patches` block) | users expect one ignore list; repos that never opted in do not start failing | -| 6 | Defaults `test/ tests/ fixtures/ __fixtures__/ testdata/` first, overridden by `!`; discovered roots only | moves H1; replace-on-set would re-enable fixtures on any unrelated edit | -| 7 | Strict validation of `patches`, fail closed, exit 1 `socket_yml_invalid` | a broken narrowing rule must not widen the rollout | -| 8 | Both files: error only if the parts we read differ | consumers disagree on precedence; repos that have both keep working | -| 9 | Repo root = nearest trusted `.git` ancestor (ceiling dirs honored), else `--cwd`; root files only; PATHs outside it are exit 2 | matches the GitHub App; memory can mirror it; never reads outside the checkout | -| 10 | Flags intersect lists; scalars CLI > env > file > default; `--no-socket-yml` with env | contract precedence and "every flag has an env var" | -| 11 | `maxNewPatches: 0` = upgrades only; absent / `none` = unlimited | literal meaning; avoids the Dependabot/Renovate 0 disagreement | -| 12 | Unknown severity is filtered when a floor is set | fail closed | -| 13 | One data source (by-package records) for floor, supersession, classification and order | selection, classification and reporting can never disagree | -| 14 | NEW per (project root, base purl); budget per base purl; memory run-wide, disk per invocation carried across directories | a widened pilot re-enters the cap; one package in many roots costs 1 | -| 15 | Upgrades exempt from the cap | rollout risk is per package; keeps patched packages current | -| 16 | Order: severity, advisory count, ecosystem, base purl, uuid; no `publishedAt` | total and time-independent | -| 17 | Eligibility = everything the planning pass can decide; fetch-all references; incomplete lookups admit no NEW rows | a broken patch never holds a slot; failures never reshuffle the queue | -| 18 | Filtered packages with recorded patches are retained, never removed or upgraded | narrowing freezes, never removes | -| 19 | `get` bypasses the policy with a warning | explicit intent | -| 20 | Separate `policy` (A) and `rollout` (B) JSON blocks | clean ownership seam; both additive | -| 21 | depscan reads the policy from the base SHA for PR jobs too | a PR cannot loosen the policy judging it | -| 22 | Everything ships in 5.0 | honoring `projectIgnorePaths`, disk default ignores and fail-closed file errors change scan's default behavior (MAJOR) | - -## 9. Work items - -Both items branch from `release/v5-prerelease` (suggested branches -`v5/rollout-policy` for A, `v5/rollout-limit` for B). **Merge order: A, -then B.** B rebases onto A and owns the final integration (9.3). The -seams are small and listed in 9.0: the step 5 → step 7 `Offers` struct -(A), the repo-relative path helpers (A), the file's `maxNewPatches` value -(A → B), and the pipeline order. - -### 9.0 Shared contract (frozen by this plan) - -Scan pipeline, in order (disk and memory): - -1. load policy (A); fail closed before any write -2. crawl; capture the prune universe (unchanged) -3. root filter, ecosystem/package filter, retained set (A) -4. batch API, by-package details (unchanged fetches) -5. candidate severity filter on by-package records (A); `discover_selected` - returns `Offers` (below) so B sees both the unfiltered and the - floor-filtered candidates -6. per-package ranking (unchanged `ranking`) -7. classify, planning pass for eligibility, budget, deferral (B) -8. writers (receive only admitted NEW rows, ALREADY rows with the recorded - uuid, and UPGRADE rows) - -```rust -// crates/socket-patch-core/src/policy/mod.rs — OWNER A -pub struct SelectionPolicy { /* private fields */ } -pub enum PolicySource { None, File { path: String, sha256: String }, Bypassed } -pub enum FilterReason { - Disabled, PathExcluded { pattern: String, list: &'static str }, PathNotIncluded, - Ecosystem, PackageNotListed, PackageIgnored { spec: String }, - Severity { found: Option, floor: String }, -} -impl FilterReason { pub fn code(&self) -> &'static str; pub fn detail(&self) -> String; } -pub enum PolicyError { - Invalid { file: String, key: String, message: String }, - Ambiguous { files: [String; 2] }, -} -impl PolicyError { pub fn code(&self) -> &'static str; } // socket_yml_invalid | socket_yml_ambiguous -pub enum RootFile { Absent, Present(Vec), PresentWithoutContent } -pub trait PolicyFs { fn read_root_file(&self, name: &str, cap: usize) -> std::io::Result; } -pub enum OverrideSource { Flag, Env } -pub struct PolicyOverrides { pub bypass: bool, pub min_severity: Option<(Option, OverrideSource)> } // (None, _) = "none" -pub struct PolicyWarning { pub code: &'static str, pub detail: String } -pub struct Root<'a> { pub rel_dir: &'a str, pub markers: &'a [String], pub explicit: bool } -impl SelectionPolicy { - pub fn unrestricted() -> Self; // built-in default ignores only - pub fn load(fs: &dyn PolicyFs, o: &PolicyOverrides) -> Result<(Self, Vec), PolicyError>; - pub fn source(&self) -> &PolicySource; - pub fn enabled(&self) -> bool; - pub fn admits_root(&self, root: &Root) -> Result<(), FilterReason>; - pub fn admits_purl(&self, purl: &str) -> Result<(), FilterReason>; // ecosystem + packages - pub fn admits_severity(&self, severity_order: u8) -> Result<(), FilterReason>; - pub fn max_new_patches(&self) -> Option; // the file's value; None when source() is None or Bypassed, or the key is absent -} -pub fn package_spec_matches(spec: &str, purl: &str) -> bool; // moved from cli scan/mod.rs:383 -pub fn find_repo_root(cwd: &Path) -> PathBuf; // 4.5 -pub fn repo_relative(repo_root: &Path, dir: &Path) -> String; // "" for the repo root, `/` separators - -// crates/socket-patch-core/src/policy/mod.rs — OWNER A (the step 5 → 7 seam) -pub struct Offers { - pub unfiltered: BTreeMap>, // purl → every offer (after tier) - pub selected: BTreeMap, // purl → winner among floor-admitted offers -} - -// crates/socket-patch-core/src/rollout.rs — OWNER B -pub enum Recorded { None, Same, Kept { uuid: String }, Superseded { old_uuid: String } } -pub struct Candidate { - pub project: String, pub purl: String, pub base_purl: String, pub uuid: String, - pub ecosystem: &'static str, pub severity_order: u8, pub advisory_count: usize, - pub recorded: Recorded, pub eligible: bool, pub in_flight: bool, -} -pub enum MaxNewSource { Flag, Env, File, Default, Cap } -pub struct MaxNew { pub value: Option, pub source: MaxNewSource } -pub fn resolve_max_new(flag: Option>, env: Option>, - file: Option, cap: Option) -> MaxNew; -pub fn canonical_base_purl(purl: &str) -> String; -pub fn rollout_cmp(a: &Candidate, b: &Candidate) -> std::cmp::Ordering; -pub struct RolloutCounts { pub new: u32, pub deferred: u32, pub upgrade: u32, pub already: u32 } -pub struct RolloutPlan { - pub admitted: Vec, pub deferred: Vec<(Candidate, u32)>, - pub counts: RolloutCounts, - pub remaining: Option, // carried to the next directory - pub admitted_base_purls: BTreeSet, // carried too -} -// Rows whose base_purl is in `already_admitted` are admitted without spending budget. -pub fn plan_rollout(candidates: Vec, max_new: &MaxNew, incomplete: bool, - already_admitted: &BTreeSet) -> RolloutPlan; // pure - -// crates/socket-patch-core/src/api/ranking.rs — OWNER B (addition) -pub fn search_result_supersedes(candidate: &PatchSearchResult, recorded: &PatchSearchResult) -> bool; -``` - -Rules both items follow: -- Severity input is always `max_severity_order` over the by-package - record's `vulnerabilities`, never `RankKey.severity`, never the batch - list. -- Skip-reason strings are the stable codes in 4.7 and 5.5; warnings go to - scan's top-level `warnings[]`. -- JSON: A owns the top-level `policy` block; B owns the top-level - `rollout` block. Neither edits the other's. -- CLI args: A adds a `#[command(flatten)]` `SocketYmlArgs` - (`--no-socket-yml`, `--min-severity`) in `scan/socket_yml_args.rs`; B - adds a flattened `RolloutArgs` (`--max-new-patches`) in - `scan/rollout_args.rs`. Both derive `Default`; each adds its field to - the ~18 `ScanArgs` struct literals. B resolves the adjacent-line - conflicts on rebase. -- `run_project_dirs` changes: A adds the per-directory `explicit` flag; - B adds the carried remaining budget. B resolves the overlap on rebase. - -### 9.1 Work item A — socket.yml loading and filtering - -Scope: -- `crates/socket-patch-core/src/policy/{mod.rs, socket_yml.rs, paths.rs}`; - `pub mod policy;` in `crates/socket-patch-core/src/lib.rs`; move - `package_spec_matches` to core (the cli re-uses it). -- Dependencies, exact-pinned in `Cargo.toml`: a maintained YAML 1.2 serde - crate that reports duplicate keys and can refuse aliases and bound depth - (e.g. `serde_norway`; prove each property with a test, pick another - crate otherwise), and `ignore` (for `Gitignore::matched`; the top-down - walk is ours). No other new deps. -- Loader: lookup (4.5, incl. ceiling dirs and ownership), regular-file, - size and symlink confinement on the opened handle, exact-name match, - encoding, both-files rule, strict validation with key paths and - did-you-mean (4.4), `PolicyFs` for disk and memory. -- Path matcher (4.3): marker-file subject, npm-`ignore` top-down - semantics, defaults + lists in order, `includePaths`, pattern hygiene; - golden fixture generated from npm `ignore` (commit the generator script - under `scripts/` and the fixture under `crates/socket-patch-core/tests/`). -- Filters at the pipeline points in 9.0: - - disk: root filter in `project_dirs` / `run_project_dirs` - (`scan/mod.rs:1268-1320`, carrying `explicit`) and the agent project; - `admits_purl` next to `--package` (`scan/mod.rs:1490-1511`); severity - filter on by-package candidates before `select_patches` - (`discover_selected`, `scan/mod.rs:553`, and the human arm, - `mod.rs:2386-2402`); retained set computed from the recorded view and - excluded from writers. - - memory: full path policy in `selectHostedScanPaths` - (`hosted_memory/select.rs`), from the caller-supplied `policyFiles` - text (7.2, two-phase); the same root filter in the session before - `max_projects` (`hosted_memory/mod.rs:377`); `admits_purl` at - `hosted_memory/mod.rs:428-432`; severity filter before - `select_top_ranked`. -- Move `test tests fixtures __fixtures__ testdata` out of - `EXCLUDED_ROOT_SEGMENTS` (`hosted_memory/roots.rs:56-67`) into the - built-in default ignores, and apply them to disk PATH-glob expansion. -- `enabled: false` report-only path; `get`'s `policy_bypassed` warning; - `--global` ignores the file; PATHs outside the repo root → exit 2. -- Flags: `--no-socket-yml`/`SOCKET_NO_SOCKET_YML`, - `--min-severity`/`SOCKET_MIN_SEVERITY` (`SocketYmlArgs`). -- napi + hosted-bundle (7.2, A rows); `npm/index.d.ts` types. -- JSON `policy` block (4.7), human policy line (naming suppressed - critical/high), error output with `errorCode`, warnings - `socket_yml_ignored_value`, `socket_yml_name_case`, - `socket_yml_repo_untrusted`, `patches_disabled`, `policy_bypassed`; - output string hygiene. - -Tests: -- Unit (core, table-driven): every row of 4.4 in order; the npm-`ignore` - golden fixture (anchoring, bare names, trailing `/`, `!`, excluded - parents, case); marker rule (all markers ignored / any included); - defaults + negation; explicit vs discovered; package specs incl. - invalid ones; severity floor incl. unknown and `moderate`; both-files - equal / different / one invalid; lookup with `.git` dir, `.git` file, - none, `GIT_CEILING_DIRECTORIES`, foreign-owned `.git`; symlink inside - and outside, directory, FIFO; alias bomb; oversize; BOM, CRLF, UTF-16. -- Parser contract: `tests/cli_parse_scan.rs` rows for both flags and env - vars (empty = unset, malformed = exit 2). -- E2E (wiremock, `tests/in_process_scan.rs` style): hosted, vendored, - agent and `--dry-run` with a socket.yml filtering by path, ecosystem, - package and severity; invalid file → exit 1, `errorCode`, no bytes - changed; `--no-socket-yml`; narrowing after a patch is applied leaves the - pinned package byte-identical in all three modes (retained); a recorded - merged patch below a new floor is kept, not replaced; `--prune` universe - unchanged; PATH outside the repo → exit 2. -- Parity: `tests/hosted_memory_parity.rs` gains a socket.yml fixture - (single-lockfile roots) where disk and memory filter the same roots and - packages; a memory test where the tree lists socket.yml but its content - is withheld → `policyError`; a memory test where - `ignorePaths: ["!/e2e/tests/"]` re-includes a default-ignored root, so - its lockfile is selected, fetched and patched as on disk. -- This repo's own `socket.yml` keeps working (its `projectIgnorePaths` - now also excludes the fixtures from patching). - -Docs (A): `CLI_CONTRACT.md` (new "socket.yml patch policy" section: -grammar, precedence, paths, lookup, validation, commands; flag + env rows; -error codes; `policy` JSON block; the trust-boundary bullet gains the -"narrow or pace" sentence), README (scan section: "Roll out gradually" -with recipes R1-R4, R6), CHANGELOG `[Unreleased]` (Added: socket.yml -patch policy; Changed (BREAKING): scan honors `projectIgnorePaths`, -default test/fixture ignores on discovered roots, invalid socket.yml with -a `patches` block fails scan). - -### 9.2 Work item B — limit, ordering, reporting - -Scope: -- `crates/socket-patch-core/src/rollout.rs`; `pub mod rollout;` in - `crates/socket-patch-core/src/lib.rs`; `search_result_supersedes` in - `ranking.rs`, and `detect_updates` / `updates[]` switched to by-package - supersession; move the `detect_updates` call (today `scan/mod.rs:1912`, - on batch data) after `discover_selected` so it receives the by-package - offers. -- Make `discover_selected` (`scan/mod.rs:553`) the single disk selection - point: route the human agent/vendored arm (`mod.rs:2386-2402`) through - it, and add the step-7 stage after it (classify its `Offers`, planning - pass, `plan_rollout`) yielding `{admitted, deferred}`, so hosted - (`run_redirect_selected`, `hosted.rs:1196`), vendored and agent writers - receive only the rows 9.0 step 8 allows (ALREADY with the recorded - uuid). `discover_selected`'s return type is A's `Offers`. -- Classification from the merged recorded view (5.1); the planning pass - for eligibility (hosted: grants, purl/url, vlt preflight, symlink - refusals, rewriter planning; vendored: preflight; agent: partition); - fetch-all references; `rollout_reference_failed` and - `rollout_incomplete_lookup`; `plan_rollout`; the remaining budget - carried through `run_project_dirs` in sorted directory order. -- In-memory engine (7.2, B rows): pin discovery and state-file reads, - collect → plan → apply, options and result fields, `npm/index.d.ts`, - hosted-bundle fields. -- Flag: `--max-new-patches `/`SOCKET_MAX_NEW_PATCHES` - (`RolloutArgs`); `resolve_max_new` including the file value from A - (9.3). -- JSON `rollout` block (5.5), `redirect.skipped[]` mirror, human - "Rollout:" line and the Next-steps deferred line (hosted - `format_next_steps`, `hosted.rs:3457`, and the agent/vendored - summaries). - -Tests: -- Unit (core): `rollout_cmp` total order (property test: every - permutation sorts the same); `plan_rollout` caps only eligible NEW, - counts base purls, one package across roots costs 1, 0 = no NEW, `none` - = unlimited, ineligible rows hold no slot, `incomplete` admits nothing - NEW, in-flight first, remaining budget; `resolve_max_new` precedence - table incl. cap on `none`; `canonical_base_purl` twins; - `search_result_supersedes` rungs. -- E2E (wiremock): hosted, vendored, agent, `--dry-run`: 9 candidates with - `--max-new-patches 3` apply the 3 most severe; a rerun on the result - applies the next 3; a third run the last 3; a fourth changes nothing; - dry-run output equals the wet run's decisions; upgrades land regardless - of the cap; a withdrawn, a `bad_purl` and a vlt-withheld top-ranked - patch hold no slot; a failed detail lookup with a cap admits nothing - NEW; two PATH directories share one budget in sorted order; JSON - `rollout` and `redirect.skipped[]`; exit 0. -- Parity: `hosted_memory_parity.rs` single-root cap fixture: disk and - memory admit and defer the same rows. Two-root fixture: assert memory's - run-wide order and disk's per-directory order separately (they differ by - design, 5.2). A memory rerun with pins (and with a committed - manifest / vendor state) lands the next N. -- Parser contract rows for the flag and env var. - -Docs (B): `CLI_CONTRACT.md` (limit semantics: classification, -eligibility, unit, budget scope, order, convergence, version-bump and -twin notes, starvation and non-committing CI; flag + env rows; `rollout` -block; `rollout_deferred`; warnings; `jq` recipe; "Which patch gets -selected" gains the cross-package order and the by-package supersession -change), README (recipe R5, `--max-new-patches`), CHANGELOG -`[Unreleased]` Added (and Changed: `updates[]` uses by-package data). - -### 9.3 Integration (B, after rebasing on A) - -- Pass `policy.max_new_patches()` as the `file` layer of `resolve_max_new`. -- Resolve the `ScanArgs` struct-literal and `run_project_dirs` conflicts. -- Combined e2e: a socket.yml with `includePaths`, `minSeverity: high` and - `maxNewPatches: 2` over a two-root fixture, disk and memory, three runs to - convergence, asserting each engine's own budget scope (5.2); - `--no-socket-yml` drops the file's cap but keeps a flag cap. -- Switch `Candidate.project` to A's `repo_relative` and consume A's - `Offers` (before A lands, B uses canonical `--cwd` as the repo root and - treats the selected offers as the unfiltered list). -- If B is ready before A merges, B ships with the file layer passed as - `None` and wires it in a follow-up commit on its branch once A lands. - -### 9.4 Work item A: decisions made while building - -Gaps and contradictions A resolved with the smallest reasonable decision -(each is also in A's PR description): - -1. **YAML crate.** `serde-saphyr` 1.3.0 (maintained, YAML 1.2), driven - through its re-exported event parser (`serde_saphyr::granit_parser`, no - extra dependency) into a small node tree. Aliases are never expanded, so - an alias bomb anywhere costs nothing, and anchors / aliases / merge keys / - custom tags are refused only inside `patches` and `projectIgnorePaths` - (an anchor in `issueRules` keeps working). Duplicate keys and the depth - bound are enforced while building the tree. `serde_norway` was not - picked: its libyaml core expands aliases with only a global repetition - limit and cannot refuse them per subtree. Unit tests prove each property. -2. **Disk markers** are the in-memory engine's lock markers (plus the - Maven/NuGet markers disk scans support); manifests are not markers. - With `package.json` as a disk marker, `ignorePaths: ["**/package-lock.json"]` - would never exclude a disk root while excluding the same root in memory. -3. **Whole-file errors.** YAML syntax, duplicate keys, a non-mapping top - level, depth and a second document are errors even without a `patches` - block (the file cannot be known not to have one). `patches: null` counts - as present for the version gate; a key under `patches` with no value is an - error, never "default". -4. **`enabled: false`** reports recorded packages under `retained[]` - (`policy_disabled`) and every other candidate under `filtered[]`. -5. **Floor vs recorded patch** (until B's `search_result_supersedes`): a - recorded package keeps its recorded patch when it outranks every - floor-admitted patch in the canonical ranking, or when nothing passes the - floor; otherwise the admitted winner is selected, exactly as without a - floor. -6. **Retained packages** stay in the batch query (so `upgradeAvailable` can - be reported) but never reach selection or a writer. -7. **PATH-glob matches under a default ignore** are still visited as roots - and root-filtered (one `purl: null` entry), so a recorded patch there is - reported as retained. -8. **In-memory engine gaps until B lands its recorded view**: `retained[]` - is empty and the floor rule of item 5 cannot see recorded pins (filtered - packages' pins stay byte-identical regardless: the rewriters only touch - selected dependencies). A root named in `projectRoots` is explicit and - skips the defaults. There is no case-variant warning in memory - (selection reads exact names only). `ProjectResult.skipped[]` carries the post-lookup policy reasons - (severity, disabled); the pre-lookup ones are in the session `policy` - block only. -9. **Session option `policyPaths`** (selection's list, handed back like - `projectRoots`) is how the session tells "listed but never sent" from - absent. Two-phase selection (7.2) names its outputs: selection returns - `policySha256` (`null` without a file) and the session takes it as an - option, since 7.2 does not say how the session learns what the - selector saw; a session that reads a policy file without it fails - closed. Selection also takes `noSocketYml` so both sides bypass - together; a bypassed session given a digest fails closed. A root the - selector excludes is reported in its `ignoredSample` with the - `policy_*` reason and never streamed (streaming its markers would count - every fixture lockfile against `maxFiles`), so in memory - `policy.filtered[]` lists only the roots the session received. -10. **Env layer of `--min-severity`** is read by scan, not clap, so the - `policy` block can say `source: "env"`; a malformed env value exits 2 at - run time, a malformed flag at parse time. -11. **README recipes**: R2-R4 and R6 ship without `maxNewPatches` lines (A - validates the key but does not enforce the cap); R1 and R5 come with B. -12. **`get`'s `policy_bypassed`** is one warning per package; the severity - reason fires only when none of the package's patches passes the floor. -13. **Repo-root trust** (review follow-up): root trusts every `.git` owner - and `SUDO_UID`'s user is trusted, so a root CI container over a checkout - owned by another uid still applies the policy (distrust would drop a - policy that only narrows). A `.git` symlink counts, as in git. -14. **A disk root with no lockfile** uses its manifests as markers, so - `includePaths: ["/*", "!/*/"]` can match a lockfile-less repo root. -15. **Top-level typos and merge keys fail closed**: a key within two edits - of `patches` starting `pat`/`pac`, and a top-level `<<` or aliased key, - are errors (another YAML reader could see a `patches` block there). -16. **Report-only `--json`** fetches patch details only when a floor or - `enabled: false` could withhold something, so its `filtered[]` matches - the human output. -17. **What the floor reports**: the top-ranked patch it withheld, when the - package ends up unpatched or held at its recorded patch; not when a - lower-ranked admitted patch wins. A kept recorded patch that is itself - below the floor is not a skip. - -## 10. Open questions (decided by default, revisit with evidence) - -- A separate upgrade cap (`maxUpgrades`) if server-side republishes rotate - too many pins at once. Default: none. -- CVSS/EPSS/KEV or reachability as ordering keys once the patch API - exposes them; they would slot between severity and advisory count. -- A generated JSON Schema for the `patches` block, shared with depscan and - the docs, to keep validators from drifting. -- Recognizing a dependency version bump of an already-patched package as - exempt from the cap (needs state hosted mode does not keep). - -## 11. Implementation notes (work item B) - -Where the plan left a gap, work item B made the smallest decision that -keeps its rules intact: - -- **`updates[]` without by-package data.** A `--json` report-only run - (`--prune` / `--global` with no mode) fetches no by-package records, so - its `updates[]` stays on the batch rungs (`batch_supersedes`). In every - other run `updates[]` is the UPGRADE rows, plus the batch-derived entry - for a package the by-package lookup returned no offer for (nothing was - selected there to disagree with). -- **Report-only and empty scans** carry the `rollout` block with zero - counts: they plan nothing. -- **Unrecognized hosted pins.** Discovery only treats URLs on - `patch.socket.dev` or a `--patch-server-url` origin as hosted pins. A - scan against another server without that flag would read every pin as - NEW and re-spend the same N slots forever. The hosted gate therefore - also counts a NEW row as ALREADY when a lockfile names its selected - uuid (uuids are unique; one linear scan per file). -- **In-memory recorded view.** The engine has no disk discovery, so a - root's hosted pins are the offered uuids of each purl that its own - files mention (nested roots' files excluded), merged with the tree's - `.socket/manifest.json` (now selected by `selectHostedScanPaths`) and - `.socket/vendor/state.json` at the disk precedence. A pin to a patch - the API no longer offers reads as NEW: it costs one slot once, and the - next run sees the new pin. -- **Option source.** The in-memory `maxNewPatches` option reports - `source: "flag"` (it is the caller's explicit layer); `maxNewPatchesCap` - reports `cap` when it tightens the value. -- **Key 6 across a base purl's rows.** Rows are sorted with - `rollout_cmp` and a base purl takes the rank of its first row, which is - the "minimum key over its rows" of 5.2; the uuid key only orders rows of - one base purl, which are admitted or deferred together. -- **Reference failures.** On disk the reference lookup is one call; when - it fails in a capped run whose rows are all NEW, the rows are deferred - with `rollout_reference_failed` and `rollout_incomplete_lookup` instead - of failing the run. In memory the same rule applies per root. -- **Human output.** The `Rollout:` line prints only when a cap is set. - Hosted mode appends the deferred lines to its existing next steps; - agent and vendored mode print them under a `Next steps:` heading. -- **Lock.** A wet hosted run whose only candidates are NEW rows it cannot - admit (budget 0, or incomplete data) takes no apply lock and writes - nothing, `.socket/` included. -- **Folding.** `canonical_base_purl` is discovery's, so a nuget or - composer pin (lowercased) and a pypi pin (PEP 503 name) match the API's - spelling, and a package in two spellings is one budget unit. Every hosted - pin joins the recorded index, not just the first per key, so both pinned - qualifier twins read ALREADY. -- **Flag over env.** An explicit `--max-new-patches` wins without parsing - `SOCKET_MAX_NEW_PATCHES`; whitespace-only env values are unset. -- **Known limits.** (1) In memory, the symlink / unreadable-file refusals - run inside the first rewrite, before the plan, so a candidate file that - only a deferred NEW row would rewrite still refuses its root (disk runs - its symlink guard after the gate). (2) On disk, a project directory that - fails outright spends nothing and does not freeze later directories. (3) - A NEW row that `mark_pinned` turns ALREADY in a run that could admit no - NEW row takes the apply lock only after its files were read. (4) Memory - pin evidence is any fetched text file of the root; disk's is its - discovery plus the candidate files. (5) No e2e case covers a - vlt-withheld top-ranked row; it takes the same ineligible path as the - withdrawn and `bad_purl` rows the e2e tests cover. -- **socket.yml layer.** B resolves the cap as flag > env > file > - unlimited through `resolve_max_new`; the file value is A's - `SelectionPolicy::max_new_patches()` (none when bypassed). The rollout - classifies what A's selection keeps: a retained package is neither NEW - nor an UPGRADE, and a severity floor removes a NEW row before it can - take a slot (9.3). The in-memory engine resolves the cap after the - session's socket.yml loads; a session that fails on it has no - `rollout` block. diff --git a/docs/design/v5-plan.md b/docs/design/v5-plan.md deleted file mode 100644 index 9a516aa13..000000000 --- a/docs/design/v5-plan.md +++ /dev/null @@ -1,227 +0,0 @@ -# v5 plan (branch `release/v5-prerelease`, PR #277) - -Decided 2026-09-27 by the project owner. Each workstream is its own branch -cut from `release/v5-prerelease` and its own PR back into it. Signed commits, -explicit push refspecs (`git push origin HEAD:refs/heads/`), never -push to `main`. - -Supporting analysis (session reports, summarized here): stale-doc audit -(567 findings, fixed), complexity-vs-value inventory, duplicated-code map, -patch-UI review. - -## Product decisions - -- **Workflow:** `scan` (hosted, default, no prompts) → `vex` → `vendor` - (eject to `.socket/vendor/` for offline) + `list`. `get` defaults to hosted - too (done). -- **vlt stays** in every mode (hosted, vendored, agent). Not a cut candidate. -- **Every package-manager version we support stays** (pnpm 1–10 incl. 7/8 - vendored, bun.lockb, yarn classic + berry, pipenv/pdm/poetry/hatch/uv, - bundler eras, …). Version support is not negotiable. -- **Agent mode** is deprecated over time but stays in v5. **`setup` is - removed in v5** (install hooks: npm postinstall, the pypi `.pth` hook - wheel, the Bundler plugin gem, Composer). `apply` stays (users wire it - into CI themselves). -- **Hosted ledger (`.socket/vendor/redirect-state.json`) is removed.** - `scan`/`get` hosted write only lockfile edits. Rollback of hosted wiring - no longer replays recorded fragments. -- **In-place vendored ledger re-synthesis in `repair` is cut**; repair - re-downloads artifacts from the remote instead (see WS5 caveat). -- **Future work (not v5):** a better vendored story for Maven and NuGet - (vendored Maven refuses multi-module/Gradle; NuGet feed is fragile). - Keep the current behavior; do not invest further now. - -## Workstreams (ordered; WS1–WS3 unblock the rest) - -### WS1 — Ledger-free hosted mode + new rollback *(branch `v5/ledger-free-hosted`)* -- Start from local WIP `wip/v5-ledger-free-hosted` (6426bd68: scan stops - writing the ledger; broke ~230 hosted round-trip tests). -- Hosted rollback/remove: for each hosted pin discovered from lockfiles - (`vex::discover` refs), restore the **default upstream** entry: re-resolve - the registry artifact for `name@version` (npm registry tarball + integrity, - PyPI JSON, crates index, rubygems, packagist, proxy.golang.org, maven - central, nuget v3) and rewrite the lock entry with the same per-format - writer used for hosted (WS3 LockModel). Where that is impossible - (formats with non-derivable fields, offline), refuse with a clear - `git checkout -- ` remedy. No fragment replay. -- Keep *reading* a legacy `redirect-state.json` only for migration (list/vex - may show its records; rollback may delete it). Never write it. -- vex/list/vendor/scan-updates derive hosted state from lockfiles only. -- Rewrite the ~230 affected tests to the new contract; update - CLI_CONTRACT/README/CHANGELOG. - -### WS2 — `vendor` ejects hosted projects *(branch `v5/vendor-eject`)* -- Standalone `vendor` today no-ops without `.socket/manifest.json` - (vendor.rs ~672). New behavior: with no manifest, take the patch set from - the hosted pins in the lockfiles (uuid in the hosted URL), fetch records - from the API, vendor each into `.socket/vendor/`, and rewire the lock - from hosted → vendored (reuse `scan --mode vendored` takeover path, or - WS1's upstream-restore + vendored rewrite). -- `vendor --revert` → back to upstream (WS1 mechanism), not hosted. -- `lib.rs` after_help line "socket-patch vendor Eject…" becomes true; - README tutorial/“Work offline” switch back to `socket-patch vendor`. - -### WS3 — One lockfile model per ecosystem *(branch `v5/lock-models`)* -- Today pnpm-lock.yaml has 7 readers (redirect/mod.rs pnpm, vendor/pnpm_lock, - pnpm_lock_legacy, lock_inventory/pnpm, lock_inventory/wired+recover, - get.rs:1511 heuristic, repair_vendor scan_vendor_references); cargo 3 - grammars (redirect/mod.rs:1059–3261, vendor/cargo_lock+cargo_manifest, - takeover.rs); gem 2; composer 3; yarn/bun partially shared. -- Target: `core/formats/` per lock format, parse once, exposing - `entries()` (inventory), `wired_refs()` (vex discover + repair), - `plan_hosted()`, `plan_vendored()`, `restore_upstream()` (WS1), `in_use()`. - Follow the `utils/python_lock.rs` pattern (already shared by disk + memory). -- One PR per family: pnpm (incl. legacy — support must stay) → cargo → gem → - composer → yarn/bun/npm/vlt → go/maven/nuget. -- Gate: redirect golden fixtures (shared with depscan TS), the - `*_equivalence_tests`, vex discover goldens, lock_inventory tests, - byte-exact CRLF output. -- Also unify the 4 "which files carry wiring" lists into `formats::registry()`. - -### WS4 — One hosted engine, disk + memory *(branch `v5/one-hosted-engine`)* -- Both functions stay: disk `scan/get --mode hosted` and the in-memory - engine (`hosted_memory/`, used by `socket-patch-node` and `hosted-bundle`). -- Extract plan → rewrite → edits from `run_redirect_selected` - (scan/hosted.rs:1205–3358, 2.1k LOC) into a pure core function over - `ProjectView`; `hosted_memory` calls it (delete its redirect.rs/ledger.rs - copies, ~2.5k LOC); disk keeps only lock, probes, symlink guard, commit. - Move the engine to core so `socket-patch-node` stops depending on the CLI - crate. Keep `hosted_memory_parity` green until the final commit. -- Depends on WS1 (no ledger delta to merge) and benefits from WS3. - -### WS5 — Consolidate vendored apply/revert wrappers + cut ledger rebuild *(branch `v5/vendor-backend`)* -- Apply wrappers (4): `vendor.rs run/run_vendor`, `scan/vendor_flow.rs` - (json/interactive/preview/legacy + 7 `boxed_*` shims), `get.rs - run_get_vendored`, `repair_vendor.rs` (1.2k-LOC fn). Revert wrappers (3): - `vendor.rs run_revert`, `rollback.rs run_vendored_leg`, `remove.rs - revert_vendored_matches`. → one `VendoredBackend { apply, revert, repair }`. -- Cut `repair`'s vendored-ledger re-synthesis from lockfiles; repair - re-downloads missing/corrupt artifacts from the vendoring service/remote. -- **Caveat to verify first:** the local rebuild path (`vendor/npm_pack.rs`, - `pypi_wheel.rs`, `berry_zip.rs`, `registry_fetch.rs`, `prestage.rs`) may be - what depscan's server-side vendoring uses via the CLI for packing. Check - `../depscan` (grep for `socket-patch`, `vendor-source`, `npm_pack`, - `hosted-bundle`, napi usage) before deleting anything; if used, keep it as - a library path. -- **Depscan check (done 2026-09-27 against SocketDev/depscan master 784013d6; - re-verified from a fresh clone by the WS5 routine — no spawn/exec of - the CLI, no Cargo/napi dependency on socket-patch crates):** - depscan does **not** use the CLI's local rebuild/pack path. - - Server-side prebuilt packages (what patch.socket.dev and the CLI's - `--vendor-source service|auto` download) are built by depscan's own - TypeScript **patch-package-converter** (`workspaces/patches/src/repack/`: - per-ecosystem repackers, upstream downloaders, `berry-cache-zip.ts` — a - TS port of `berry_zip.rs`, not a call into it). It re-downloads the - upstream archive, verifies `before_sha` + the registry digest, applies - the patched bytes and repacks. No spawn/exec of `socket-patch`, no napi. - - The `socket-patch` binary appears in depscan only as: the - `submodules/socket-patch` build for the autotester image and dev tools - (`tools/validate-patch.ts`, `tools/patch-mode-smoke.ts`) — both drive - `apply`/`scan`; `pnpm dlx @socketsecurity/socket-patch apply` postinstall - snippets; the `@socketsecurity/socket-patch/schema` manifest-schema - re-export; and the api-v0 e2e suites (`89`–`94_socket-patch-vendor-*`, - `82_…telemetry-coverage` runs `repair` on an empty manifest) that drive - the real CLI against the live API. `hosted-bundle`, `vendor-source`, - `npm_pack` and `socket-patch-node` have no production references. - - Consequence: `npm_pack.rs`, `pypi_wheel.rs`, `berry_zip.rs`, - `registry_fetch.rs`, `prestage.rs` are **CLI-internal**. They stay for - now anyway: they are the CLI's own `--vendor-source build` / `auto` - fallback (offline and service-outage vendoring) and `prestage.rs` + - `registry_fetch::artifact_matches_integrity` also serve the service - path. Dropping the local build is a separate product decision (it - would make vendoring service-only), not part of WS5. - - Side note for WS1: `workspaces/app/src/autopatch-pr/github-patch-pr-hosted.ts` - still writes `.socket/vendor/redirect-state.json` into hosted PRs so a - post-install `socket-patch vex` can attest them; WS1's "never write the - ledger" needs a depscan follow-up (or vex keeps reading it). -- **Done in WS5:** `commands/vendored_backend.rs` owns `VendoredBackend { - apply, revert, repair }`. `vendor`, `scan --mode vendored` (JSON and - interactive arms) and `get --mode vendored` all go through `apply` - (in-memory staging → `vendor_records_reusing` → per-package ledger - persist); `vendor --revert`, `rollback`'s vendored leg and both of - `remove`'s paths go through `revert`; `repair` goes through `repair`, - which health-checks ledger entries and re-vendors broken ones through the - same `apply` engine (patch.socket.dev prebuilt first under the default - `--vendor-source auto`, local build as the fallback). Lockfile references - with no ledger entry are reported (`vendor_ledger_missing`, an - artifact-level event with `uuid` + `details.{ecosystem,path}`), never - re-synthesized. Cut with it: the gem Gemfile wiring reconstruction and - empty-wiring backfill, the unverified npm "rebuild to the wired - integrity" rung (`registry_fetch::fetch_npm_unverified`), soft - fingerprint-less restores, and `details.ledgerRestored`. -- **Behavior notes (WS5):** repair now inherits `vendor`'s pristine-source - ladder and messages, so (a) a drifted installed copy of a release-variant - ecosystem (gem/pypi) fails the installed-variant probe and is reported as - `vendor_artifact_unrepairable` ("no installed package found on disk") - instead of being force-overwritten; (b) the old ledger-recovery detail - strings are replaced by the engine's. The carried-inventory refresh - (`vendor_inventory_refreshed`) and fingerprint post-verify are kept. - -### WS6 — Unified ledgers/context *(branch `v5/project-context`)* -- After WS1 only two stores remain (manifest for agent mode, vendor - `state.json`). One `Ledgers` view with one owner-precedence rule replaces - the 7 merge implementations (list combined_entries, fold_vendor_records, - scan merge_ledger_records_for_updates, vex_sources plan/build_candidates, - classify_overlap_takeover, rollback, remove) and the 61 load sites. -- `ProjectContext` (crawl snapshot, lock set, ledgers; lazy) shared by - scan/vendor/vex/list/get; `get` reuses scan's discovery instead of - get.rs:1583. - -### WS7 — Remove `setup` *(branch `v5/remove-setup`)* -- Delete the `setup` subcommand, core/setup/**, package_json/** helpers only - setup uses, the setup-matrix CI job, and the Bundler plugin gem + - `socket-patch-hook` wheel publishing. Keep `apply`. - Docs: agent mode = `scan --mode agent` + `socket-patch apply` in CI. -- **Status (branch `v5/remove-setup-and-ui`):** subcommand, core `setup/` + - `package_json/`, setup tests, `setup-e2e` feature, setup-matrix CI job, - `tests/setup_matrix/`, `scripts/setup-matrix.sh` and the setup-only - `Dockerfile.gem-b1`/`gem-b4` are deleted. vex's "Property 7" filter went - with it (agent patches attest on verification; `setup.manual` is parsed - but ignored). The v5 distribution cleanup removes the PyPI and RubyGems - CLI packages and both hook packages, including their sources, tests, - publishing workflows, wheel builder, and version-sync entries. The - supported distributions are the standalone binary via `install.socket.dev` - (preferred), Cargo crates, and npm (required by the official Socket CLI). - Previously published package versions remain available for older users. - -### WS8 — Patch UI streamlining *(branch `v5/ui`)* -- `-h` shows ~8 options (hide_short_help for the rest); hide deprecated - `--apply/--vendor`; one-line npm allow-remote note; no `(code)` tags in - human warnings; "hosted" not "redirect" in human text; one shared - Next-steps renderer; hosted/vendored `get` without prompts; `list` without - manifest says "No patches in this project"; unify cancel/upsell strings; - exit 2 for all usage errors; scan/get JSON onto `json_envelope`. -- Full item list: 22 findings from the UI review (sizes S/M/L, contract flags). -- **Status (branch `v5/remove-setup-and-ui`):** done — short `-h` - (`cli_command()` hides the rest; `--help` unchanged), hidden - `scan --apply/--vendor`, one-line npm allow-remote note (`--verbose`/JSON - keep the detail), code-free `Warning:`/`GC: skipped:` lines (error lines keep their code), - "hosted" wording in human text, `ui::next_steps` shared by hosted and - vendored, prompt-free hosted/vendored `get` (JSON too), `list`'s - `No patches in this project.` line (exit 0, empty success envelope in JSON; was 1 missing, - 0 empty), `ui::CANCELLED` / `ui::PAID_UPGRADE`, exit 2 for `get` and - `rollback --one-off` usage errors. **Not done:** scan/get JSON onto - `json_envelope` (larger contract change; deferred). Per-row - `[error] ()` / `[would-refuse]` lines keep their codes - (grep-able under `--silent`). - -### WS9 — Staged patch rollout *(branches `v5/rollout-policy` (A), `v5/rollout-limit` (B))* -- Added 2026-09-28 at the owner's request. `socket.yml` `patches:` policy - (paths, ecosystems, packages, severity floor, enabled) read by `scan` - and the in-memory engine, plus `scan --max-new-patches` (severity-ordered - per-run cap on new patches). Full plan and the two work-item specs: - `docs/design/staged-rollout.md`. Merge order A then B. - -## Remaining small follow-ups -*(All done on `v5/remove-setup-and-ui`: the vacuous rows are dropped, -GEM_PATCHES has both patches, `tool_command` and the deprecated aliases — -plus the CI grep that guarded them — are removed, and the backtest label is -retired.)* -- ci.yml `e2e_cargo`/`e2e_golang` rows select `--ignored` but have no ignored - tests (vacuous legs) → give them `--include-ignored` or drop the rows. -- `e2e_vendored_production` GEM_PATCHES lacks merged `01019627` (v5 ranking - picks it) and `9c2b4925`. -- `utils::process::tool_command` has no prod callers. -- Deprecated re-export aliases in core (`patch/mod.rs`, `lib.rs`, - `utils/mod.rs`) — drop in v5. -- `scripts/backtest-poetry.py:541` "known crawler gap" label. diff --git a/docs/design/v5-waste-review.md b/docs/design/v5-waste-review.md deleted file mode 100644 index 1d1f89c43..000000000 --- a/docs/design/v5-waste-review.md +++ /dev/null @@ -1,360 +0,0 @@ -# v5 waste review: socket-patch + depscan patch system - -> Reference copy of PR #286, which was closed without merging. Each -> finding's owner (workstream, in-flight PR or owner decision) is in -> the [triage map](https://github.com/SocketDev/socket-patch/pull/286#issuecomment-5869109317). - -Scope: socket-patch at `release/v5-prerelease` (8ae7dc37; in-flight branches -#279–#283 and `v5/integration` f8b8d80a where noted) and depscan `master` -(repack in `workspaces/patches/src/repack`, serving in -`workspaces/patches/src/services/patch-serving` and -`workspaces/patches-api-proxy/src/server.ts`, api-v0 endpoints). Respects the -owner decisions in [v5-plan.md](v5-plan.md): vlt stays, every PM version -stays, `setup` goes, hosted ledger goes, maven/nuget vendoring is frozen, and -WS5 (#283) keeps the local rebuild. Nothing here proposes dropping vlt or any -PM version; CI tiering only moves legs between PR, main push and nightly. - -Companion: [repacking-to-depscan.md](repacking-to-depscan.md) (what each repo -builds and what moving the rest of repacking to depscan would take). - -## Summary - -**Method.** Both repos were inventoried: the CLI's local rebuild, the -per-ecosystem builders, hosted/napi, depscan repack, depscan's use of the -CLI, CI and test cost, and churn and bug history. Findings were swept over 9 -dimensions: cross-repo duplication, intra-repo duplication, dead code, test -overlap, CI matrix, redundant network, repacking, expensive abstractions, and -high-cost/low-value features. A gap review then covered the diff channel, -the upstream fetchers vs the CLI pristine ladder, signing, fallback-rate -observability, patches-harness-contract, patch-publication, the cost of the -in-flight PRs, and the depscan bump break list. Each finding was -independently re-verified on three criteria: facts (re-measure every -claim), value (is it really waste, and does it conflict with owner -decisions?) and savings (≥150 LOC or ≥2 CI job-min/run). A finding was kept -when at least two held. Verified numbers replace the initial estimates. - -**Counts.** 85 raw findings were de-duplicated to 75, and the gap round -added 31 (106 reviewed). 80 were kept and 26 dropped. Of the 80 kept, 69 are -waste (ranked below) and 11 are measurements or checks that found no waste. - -**Top line (net new, after de-duplicating against v5-plan WS1–WS8 and PRs -#279–#283):** -- Actionable now: about **32.8k lines**: 9.1k code, 14.9k test, and 8.8k of - docs and workflow YAML. -- Gated on a precondition or owner decision: a further **15.7k lines** (6.3k - code, 9.4k test). 10.5k of that is the depscan TS rewriter twin (F01). -- CI: about **478 job-min per socket-patch `ci.yml` PR run**, or 438 on a - main push, against a 945 job-min main-push run. Add about 95 job-min - across the compatibility workflows per PR push that triggers them (F55 65 - pdm, F57 12 npm/pnpm, F56 ≈10 vlt, F54 8 pdm Windows; pdm-compat alone - ≈73), and about 9.5 per depscan api-v0 CI run (roughly 130 runs a day). -- The biggest single lever is build-once fan-out for the e2e matrix (F51, - 280 job-min per run). The biggest code/test levers are the #257 - equivalence oracles (F03, 6.5k), the depscan TS rewriter twin (F01, 10.5k, - gated) and depscan's stale refactor docs (F02, 8.2k lines). -- Precondition for reading any v5 CI: the base branch is red on one - assertion (F77), so the e2e tier has not run on any v5 PR. - -## Ranked findings - -Rank is verified savings × confidence (3/3 upheld over 2/3) × low risk. -Runtime-only findings (0 LOC, 0 CI) rank by avoided work per run. `sp` means -socket-patch, `ds` means depscan. LOC is verified lines removed (src + test, -or YAML/docs where noted). CI is job-min per run of the named workflow. "⊂ -Fnn" means the figure is contained in another finding and is not counted -again. - -| # | id | finding | repo | category | evidence | verified LOC | CI min/run | risk | already planned? | recommendation | -|---|----|---------|------|----------|----------|-------------:|-----------:|------|------------------|----------------| -| 1 | F51 | e2e matrix recompiles the CLI and its test binary in each of 176 legs | sp | ci-matrix | .github/workflows/ci.yml:1098,1355; run 36359489402: 176 legs = 530 job-min, 2m06s compile vs 0.03s test | 0 | 280 | L | no | Per-OS `e2e-build` job (`cargo test --no-run --message-format=json`), upload the binaries, legs run the downloaded suite; pattern at vlt-compatibility.yml:143-187. Restore the CARGO_BIN_EXE path or add an override. Every leg and PM version stays. | -| 2 | F03 | ~7.5k LOC of test-only "verbatim previous implementation" oracles from #257 | sp | test-overlap | crates/socket-patch-core/src/crawlers/*/oracle.rs (2,680); crates/socket-patch-core/src/patch/redirect/pnpm_equivalence_tests.rs:1-7; xorshift constant in 23 files | 6,500 | 0.5 | L-M | no (WS3 names them as a gate) | Snapshot the generated inputs into the redirect goldens first, keep one shared test RNG, delete the crawler oracles plus their inline `mod equivalence` blocks now, and delete each rewriter oracle in its WS3 family PR. | -| 3 | F02 | depscan patches/docs/refactor: 9.4k lines; 61% of cited paths no longer exist | ds | dead-code (docs) | depscan:workspaces/patches/docs/refactor (37 files, 9,398 lines; 181/297 paths missing; README.md:3 "temporary") | 8,222 docs | 0 | none | no | Delete everything except DAG/ (1,176 lines, backfill still active); reword the dag-lift comments that cite missing files. | -| 4 | F41 | e2e-docker is a strict subset of coverage-docker | sp | test-overlap | ci.yml:1390 vs :455; 9 legs 65.1 vs 89.2 job-min; bind-mount at crates/socket-patch-cli/tests/docker_e2e_cargo.rs:34-49 | 65 YAML | 65 | L | no | Drop per-push e2e-docker, or run it nightly as the check of the full-LTO release binary (it is the only per-push run of that binary). | -| 5 | F04 | covgap_/coverage_fix_/in_process_ categories no longer mean anything; one command's tests span up to 16 binaries | sp | test-overlap | crates/socket-patch-cli/tests: covgap_* 25 files/27.6k LOC, in_process_* 38/34.3k; get_modes_e2e.rs:465 covers in_process_get_modes.rs:649 | 4,000 | ⊂ F58 | L-M | partial (WS7 deletes covgap_setup*, excluded) | When WS5/WS8 touch a command, merge its files into one suite (in-process + subprocess modules) and delete sampled duplicates. Stop adding covgap_* files. | -| 6 | F53 | Dockerfile.base release build rebuilt with no cache 27× per run; binary unused in coverage-docker | sp | ci-matrix | ci.yml:518,1421,1662; 121.5 job-min of base builds (12.9% of run) | 0 | 68 (≈35 after F41) | L | partial (setup-matrix share = WS7, excluded) | Build once, then `docker save`/load or ghcr (gha cache is unusable with `driver: docker`, ci.yml:486-494). Keep a binary for the Dockerfile.gem/deno build-time `--version` checks. | -| 7 | F55 | pdm capstone recompiles e2e_vex_build in 30 legs and repeats 7 ci.yml rows | sp | ci-matrix | pdm-compatibility.yml:151-182; run 36363939533 capstone 30 legs/91 job-min, 2m03s compile vs 9.5s tests | 0 | 65 (per pdm-compat run) | L | no | `needs: build` plus a `--no-run` test-binary artifact. Exclude the 7 cells ci.yml gates, guarded by a leg-checker like scripts/tests/test_ci_vlt_rows.py. Every PDM version stays. | -| 8 | F52 | Tier PM-version legs: boundaries on PRs, every version on main push/nightly | sp | ci-matrix | ci.yml e2e include: 176 rows, 155 version-keyed, 78 ubuntu middle rows; no `schedule` trigger (ci.yml:3-16) | 0 | ≈90 PR (≈40 after F51) | M | no | Mark middle rows `tier: full` and skip them on `pull_request`; keep them on main push, nightly and dispatch. Keep the boundary versions named in ci.yml comments on PRs. Most of the 78 middle rows are such named boundaries (bundler, pdm, hatch, vlt eras, uv 0.5.4/0.5.5, poetry lock formats, maven); about 33 carry none, so ≈90 standalone (33 × 2.75). The recorded 140 holds only if all 78 move. | -| 9 | F06 | depscan legacy/ hosts the live admin package-detail engine; it blocks the 2026-11-04 table drop | ds | dead-code | depscan:workspaces/patches/src/legacy/fetch-autopatch-package-status.ts (3,093; 68 commits); depscan:workspaces/patches/src/api/commands/review/upgrade-risk.ts:14,181-207 | 3,000 (incl. F19) | 0 | M | partial (depscan legacy/README.md:30-31) | Before 2026-11-04: make the upgrade-risk lookup one query, give detail a version-scoped path, port the admin page to the read-models, then delete the engine, poc-result.ts, queue-driven-suites.ts and their tests. | -| 10 | F01 | GitHub-app hosted PR flow keeps a ~6k-LOC TS port of the Rust rewriter; the napi engine has 0 consumers | both | cross-repo-dup | depscan:workspaces/app/src/patches/registry-rewrite (5,978 src + 5,582 test); depscan:workspaces/app/src/autopatch-pr/github-patch-pr-hosted.ts:63,308,494; depscan 9752b91237 (cargo drift) | 10,500 (gated) | 1 | M-H | partial (WS4 keeps napi; no depscan adoption plan) | After bumps past WS1 and WS4, call the Rust engine (socket-patch-node or `hosted-bundle` subprocess) and delete the TS rewriters. Freeze the TS port until then. The 141 goldens gate byte-identity. | -| 11 | F47 | cargo-vex 17-leg cross recompiles every leg; repeats e2e_safety_cargo_build | sp | ci-matrix | ci.yml:1531-1577 (18 legs/48.2 job-min); e2e safety rows 11.1 job-min; lock knob headline-only at crates/socket-patch-cli/tests/e2e_safety_cargo_build.rs:326 | 10 YAML | 30 (≈23 after F51) | L-M | no | Drop the 3 e2e_safety rows from the e2e matrix. Run a pairwise toolchain×lock subset on PRs and the full cross on main/nightly. Build once per OS. | -| 12 | F11 | depscan break list for the #279 bump: 30 loud setup e2e failures | both | cross-repo-dup | depscan:workspaces/api-v0/e2e-tests/tests/59_socket-patch-setup.js (1,344; 27 setup calls), 82_socket-patch-telemetry-coverage.js:229-262, 65_patch-telemetry.js:478-502 | 1,380 | 2 | L | partial (WS7 covers only the CLI side) | In the depscan bump past #279, delete 59_socket-patch-setup.js (the apply edge cases at :812-1114 also run `setup --yes`; move only the bun `--help` subtest at :1170 elsewhere if it is wanted) and the 82 setup case at :229-262. Retire 65's patch_setup case after an owner check. | -| 13 | F09 | Python lock family missing from WS3's PR order; 4–5 readers per format | sp | intra-dup | v5-plan.md:75-76; check_target_guards ×4 at crates/socket-patch-core/src/vendor/pypi_poetry.rs:207, pypi_uv.rs:312, pypi_pdm.rs:184, pypi_pipenv.rs:162; utils/pdm_lock.rs:129 = utils/poetry_lock.rs:105 | 1,600 | 0 | M | extends WS3 | Add a Python PR to WS3 (formats/{poetry,pdm,pipfile,pylock_uv,requirements} on utils/python_lock). One generic guard with one documented fork rule. | -| 14 | F12 | 8 npm-family vendored backends repeat one vendor/revert skeleton; pnpm vs pnpm-legacy clone survives #281 | sp | intra-dup | crates/socket-patch-core/src/vendor/{npm_lock.rs:90, pnpm_lock.rs:110, pnpm_lock_legacy.rs:287, bun_lock.rs:327} (2,076 + 1,428 LOC); 256–367 cloned lines | 1,200 | 0 | M | extends WS3/WS5 | One `NpmFlavorBackend` trait and one driver in npm_common over utils/group_commit.rs; derive Default on VendorEntry (57 literals). | -| 15 | F49 | default suite compiled twice per `test` leg (feature-set mismatch) | sp | ci-matrix | ci.yml:331-332 (`--all-features --no-run`, then default), :372-373; documented as intentional at :336-338 | 2 YAML | 18 | L | no | Use one feature set for `--no-run` and the run in test and test-release. Owner to confirm the #150 rationale. | -| 16 | F58 | 238 CLI integration-test binaries, 78 with ≤3 tests; linking dominates test/test-release | sp | test-overlap | crates/socket-patch-cli/tests (238 files; 23 with 0–1 tests); ci.yml:335-341 "~240 test binaries" | 0 | 20 (≈30 combined with F49, F04) | M | no | Consolidate into multi-module crates per command family (as tests/e2e_vex_build/), keeping `#[serial]` (565 uses in 58 files). About 21 setup binaries go with WS7 anyway. | -| 17 | F10 | CRLF/corrupt/dry-run/round-trip invariants re-tested per writer | sp | test-overlap | 79 CRLF fns in 44 files (crates/socket-patch-core/src/patch/redirect/mod.rs 11); 232 dry_run fns | 1,400 | 0.3 | M | extends WS3 | One property harness over every LockModel impl (CRLF in = out, plan+restore identity, dry run writes nothing, rerun is a no-op). Move edge cases into its fixtures. | -| 18 | F39 | 3 regenerate/reset paths; the admin routes delete Go zips before requeue and skip the gopatch refusal | ds | intra-dup | depscan:workspaces/patches/src/services/patch-package/reset-decision.ts:32-39 vs depscan:workspaces/next-app/src/pages/api/admin/patches/regenerate-range.ts:242-264 (no force guard) | 100 | 0 | L | no | Both admin routes call resetOne() in reset-ops.ts. This removes a live hazard: a range regenerate over a Go patch breaks committed go.sum pins. | -| 19 | F19 | admin package-detail "lite" engine dead since #18370 | ds | dead-code | fetch-autopatch-package-status.ts:2211-2709 and :305-352; depscan:workspaces/next-app/src/pages/api/admin/autopatch/package-detail.ts:3,27,42,47-62 | 560 (⊂ F06) | 0 | L | no | Delete now, independent of F06. | -| 20 | F24 | patches-harness-contract carries a dead autopatch-backport config module | ds | dead-code | depscan:workspaces/patches-harness-contract/src/autopatch-backport-config.ts (273) + test (143) | 425 | 0 | L | no | Delete; fix doc paths; inline the depscan:workspaces/patches/src/services/patch-publication/dependent-merges.ts:21-26 pass-through (`trx: any`). | -| 21 | F20 | purl-api-proxy keeps a full /patch/* forward that no client calls | ds | dead-code | depscan:workspaces/purl-api-proxy/routes/patch.ts (181), lib/patch-target.ts (121), lib/forward-headers.ts (57); CLI default is patches-api (crates/socket-patch-core/src/api/client.rs:1922) | 560 | 0 | L-M | no | Confirm zero traffic in gateway logs, then delete the route, guard, forward-headers, their tests and PATCHES_ORIGIN. abort-client-response and upstream-origin are shared and stay. | -| 22 | F16 | WS1 upstream/* builds a second per-format grammar outside WS3 formats/ and imports a module #281 deletes | sp | intra-dup | origin/v5/ledger-free-hosted crates/socket-patch-core/src/patch/redirect/upstream/* (8,359 @08c30b7e; 8,752 @65aa0744); formats/mod.rs:71 stub; upstream/gem.rs:61 uses removed `vendor::gemfile_lock` | 900 | 0 | M | partial (WS3 restore_upstream stub) | Rebase #280 onto integration. Split each upstream/.rs into a pure `formats::::restore_upstream(pins)` and one async resolver. This also fixes the compile break. | -| 23 | F07 | real-installer pdm/pipenv/poetry backtests duplicated in depscan (hatch and pip exist only in depscan), run against pinned CLI SHAs | both | cross-repo-dup | depscan:tools/pipeline/{pdm,pipenv,poetry,hatch,pip}-patch-backtest.py (3,759); depscan:.github/workflows/pdm-patch-compatibility.yaml:20 SOCKET_PATCH_REVISION; scripts/backtest-{pdm,pipenv,poetry}.py | 2,900 (gated) | 30 (ds, per pypi trigger) | M | no | socket-patch compatibility workflows publish versioned captures; depscan SBOM tests consume them via the submodule; delete depscan's pdm workflow and the pdm/pipenv/poetry scripts; delete depscan's hatch workflow and script only after socket-patch adds a hatch capture. F74 is the interim step. | -| 24 | F73 | depscan api-v0 shards rebuild the pinned CLI every run despite a 963 MB cache hit | ds | ci-matrix | depscan:workspaces/github-actions/src/jobs/test-api-v0.ts:82-91,146; depscan:.github/workflows/pull-request.yaml:2273-2277; 7 runs, mean 7.9 job-min | 0 | 7.5 (~130 runs/day) | L | no | Cache the binary keyed on `HEAD:submodules/socket-patch`, or build it once and share it; the 7.5 is this cache alone. Optional, not counted: a path-gated shard for the 23 patch e2e files (see D26; the filter must keep the lib/app/pipeline import paths). | -| 25 | F23 | deploy-patches prod/staging workflows are 500-line twins edited in lockstep | ds | intra-dup | depscan:.github/workflows/deploy-patches-{prod,staging}.yaml (500 each; 68-line diff; 62 shared commits) | 440 YAML | 0 | L | no | One `workflow_call` workflow plus two dispatch wrappers; keep environment protection bound to the right job. | -| 26 | F21 | hidden legacy scan spellings and the v3 SOCKET_PATCH_* env shim survive v5 | both | dead-code | crates/socket-patch-cli/src/commands/scan/mod.rs:291,312,322,326; crates/socket-patch-core/src/utils/env_compat.rs:20-68,108-117,165-178; depscan:workspaces/patches/src/test/integration/live/hosted-live.e2e.test.ts:569-571 | 450 | 0 | L (env, --detached) / M (flags) | partial (WS8 hid, kept) | In v5.0 drop `--detached` and SOCKET_PATCH_*. Drop or warn-and-map `--redirect/--apply/--vendor`. Update the depscan tests in the same bump. | -| 27 | F29 | `--one-off` on get/rollback exists only to error | sp | dead-code | crates/socket-patch-cli/src/commands/rollback.rs:98-115,1123-1158; crates/socket-patch-cli/src/commands/get.rs:506-521,2623-2657 | 260 | 0 | L | no (WS8 kept it) | Remove the flag, SOCKET_ONE_OFF, the tests and the CLI_CONTRACT/README rows in v5.0. | -| 28 | F30 | `.socket/packages/.tar.gz` is never written but still probed, overlaid and swept | sp | dead-code | crates/socket-patch-core/src/api/blob_fetcher.rs:30-38; crates/socket-patch-cli/src/commands/fetch_stage.rs:212-235,339,460; apply.rs:1048-1056 | 250 | 0 | L | no | Delete resolve_from_archive, packages_path, the pkg_present arm and the sweeps (keep the archive helpers shared with diffs). gc sweeps the leftover dir for one release. Drop `appliedVia: "package"`. | -| 29 | F57 | vlt-serve-watchdog cannot alert; npm/pnpm compatibility have no path filter | sp | ci-matrix | vlt-serve-watchdog.yml:18,28; npm-compatibility.yml:9-13; pnpm-compatibility.yml:3-7 | 0 | 12 (PR pushes) | L | no | Path-filter npm/pnpm like bun-compatibility.yml. Arm the watchdog after a manual dispatch confirms depscan #26856/#26867 in prod, or run it daily until then. | -| 30 | F54 | pdm-compat Windows native legs vacuous (47/47 SKIP, green) | sp | ci-matrix | scripts/backtest-pdm.py:484-486,1320-1324,1352-1355; job 108746808097 | 0 | 8 | L | no | Treat a bootstrap failure or 100% SKIP as ERROR. Then either fix `Scripts\python.exe` (adds ~50–60 job-min) or drop the 16 Windows rows. | -| 31 | F46 | e2e_maven/e2e_nuget/e2e_composer rows spend ~2.5 min each on 0.03 s hermetic tests | sp | ci-matrix | ci.yml:686,688-693,696; crates/socket-patch-cli/tests/e2e_nuget.rs:182,250 and e2e_maven.rs:102,229 `#[ignore]` | 13 YAML | 7 (≈3 after F51) | L | extends follow-up (v5-plan.md:134-135) | Un-ignore the 4 hermetic tests so `test` runs them; delete the 3 rows. | -| 32 | F33 | npm `.berry.zip` sidecar is built, stored, served, never read | both | dead-code | crates/socket-patch-core/src/patch/redirect/mod.rs:166 (0 reads); depscan:workspaces/patches/src/services/patch-package/build.ts:475-482; serve-decision.ts:145-157 | 150 | 0 | L | no | CLI: drop `berry_zip_url` (44 lines). depscan: keep the rebuild (it is the 10c0 source) but stop storing and serving the zip after an access-log check; api-v0 package.ts:124-133 exposes it publicly. Drop the columns later. | -| 33 | F25 | parse_memo: process-global parse caches that work around per-package re-parsing | sp | expensive-abstraction | crates/socket-patch-core/src/vendor/parse_memo.rs (275; 21 statics in 16 files) | 320 | 0 | L | extends WS3/WS6 | Delete once LockModel parses once per run through ProjectContext; add no new sites. | -| 34 | F32 | Auto/Service fallback policy hand-rolled in 7 backends; the shared helper serves only frozen maven/nuget | sp | intra-dup | crates/socket-patch-core/src/vendor/service_fetch.rs:170-265 (callers maven_repo.rs:713, nuget_feed.rs:906); golang.rs:550-563,701-731 | 220 | 0 | M | extends WS5 | `acquire_service_artifact(cfg, record, verdict_fn)` → Used/FallBack/HardFail inside VendoredBackend. Ready arms stay per backend; warning codes become parameters. | -| 35 | F27 | the GitHub app mirrors the redirect-state.json schema that WS1 deletes | both | cross-repo-dup | depscan:workspaces/app/src/autopatch-pr/github-patch-pr-hosted.ts:81,235-300,534-575 | 300 | 0 | L | partial (WS1 CLI side) | In the depscan bump past #280, stop writing the ledger. The CLI keeps legacy reads (v5-plan.md:47-48), so this is a stale writer, not an attestation loss. Fixture captures are not prunable LOC. | -| 36 | F28 | vendored path POSTs /patches/package once per uuid; the endpoint takes 500 | both | redundant-network | crates/socket-patch-core/src/api/client.rs:1429-1437; crates/socket-patch-core/src/api/vendor_prefetch.rs (601 src); depscan:workspaces/api-v0/src/endpoints/orgs/patches/package.ts:287,330 | 300 | 0 | M | no | One chunked batch reference POST per vendor run; keep per-package GETs and the breaker. Also chunk hosted scan's unchunked call (client.rs:759-776), which returns 400 above 500 uuids. | -| 37 | F18 | one-off cargo index-line backfill runs inside every converter cycle | ds | high-cost-low-value | depscan:workspaces/patches/src/services/patch-package/converter.ts:341-352; queue.ts:593-686; cargo-index-backfill.test.ts (429) | 690 (gated) | 0.3 | L | no | Gate: backlog count = 0 (added 2026-09-28, not yet drained). Then a one-shot admin script, or a flag defaulting off. | -| 38 | F14 | depscan diff channel: on-demand bsdiff task, hidden route, proxy with per-request view preflight | ds | high-cost-low-value | depscan:workspaces/api-v0/src/endpoints/orgs/patches/diff.ts:93-107; generate-patch-diff-archive-task.ts:41-56,133 (throws in a task); depscan:workspaces/patches-api-proxy/src/server.ts:1263-1345 | 1,130 (gated) | 0.5 | M | no | Needs an owner decision on CLI diff mode: D19 showed default `repair` writes diff-only sources, so the channel is not dead (see F67). Meanwhile remove the task throws and the doubled preflight. If retired, a 404 is a safe interim (crates/socket-patch-core/src/api/blob_fetcher.rs:274-281). | -| 39 | F22 | 14 of 18 CLI telemetry events are never classified server-side; the endpoint sunsets 2026-12-31 | both | high-cost-low-value | crates/socket-patch-core/src/telemetry.rs:33-57,449-913; depscan:workspaces/api-v0/src/endpoints/orgs/telemetry-discriminators.ts:17-43; telemetry.ts:145 | 450 (gated) | 0 | L | no | Owner decision. Either classify the v5 events and move to `/v1/orgs/{slug}/events` (or get the sunset extended), or delete the unread track_* wrappers. | -| 40 | F56 | vlt capstones run in ci.yml (35 rows) and in vlt-compat install-proof (70 legs) | sp | ci-matrix | ci.yml:917-955 (112.5 job-min); vlt-compatibility.yml:189-270 | 0 | 60 (≈10 beyond F51) | L | no | vlt and every vlt version stay. Put the rows on F51's build-once; install-proof excludes the 35 cells ci.yml gates, enforced by test_ci_vlt_rows.py. | -| 41 | F74 | depscan pdm/hatch workflows trigger on pypi task code they never run | ds | ci-matrix | depscan:.github/workflows/pdm-patch-compatibility.yaml:8,20,39; runs 36239865114 (72.1 job-min), 36239865149 (114.9) | 0 | 15 (⊂ F07) | L | partial (F07) | Drop the `pipeline/src/task/python/pypi/**` trigger and add the fixtures/pdm path. Cache the CLI keyed on SOCKET_PATCH_REVISION. | -| 42 | F13 | shared redirect goldens cover ecosystems unevenly; each repo keeps unshared rewriter tests | both | cross-repo-dup | crates/socket-patch-core/tests/fixtures/redirect: 141 cases (vlt 68; pnpm 2; gem/golang/uv 1; poetry/pdm/pipenv 0) | 1,200 (alt. to F01) | 0 | L-M | partial (WS3 gate) | Only if F01 is not done: move byte-asserting TS and Rust cases into shared fixture dirs, starting with pnpm, package-lock, gem, golang and uv. | -| 43 | F37 | serve-route.ts re-inlines the stream/304/HEAD logic that serve-artifact.ts centralizes | ds | intra-dup | depscan:workspaces/patches/src/services/patch-serving/serve-route.ts:158-268; #26856 had to patch both | 110 | 0 | L | no | Route through `serveStoredArtifact({headFastPath: true})`; share `makeDeny`. Metadata Cache-Control is intentionally different, so it is not drift. | -| 44 | F35 | Berry 10c0 checksum implemented twice with hand-copied fixtures; vendored CLI ignores the server value | both | cross-repo-dup | crates/socket-patch-core/src/vendor/berry_zip.rs:335; depscan:workspaces/patches/src/repack/berry-cache-zip.test.ts:1-7; crates/socket-patch-core/src/api/client.rs:1278-1280 | 120 | 0 | L | no | Both implementations stay. Share the fixtures via crates/socket-patch-core/tests/fixtures/berry_zip, read by both; vendored takes the server's yarnBerry10c0 for service artifacts. repacking-to-depscan.md goes further: its verify step 6(vi) always recomputes over the verified tgz as a runtime tripwire, and step 14 puts the vectors under tests/fixtures/served/. | -| 45 | F36 | two npm-registry tarball fetchers inside depscan | ds | intra-dup | depscan:workspaces/patches/src/repack/upstream/npm.ts:56-60,89-145 vs depscan:workspaces/patches-shared/src/registry/npm-registry-source.ts; socket-patch-publishing-tool.ts:1264-1268 | 110 | 0 | L-M | no | Make npm.ts an adapter over fetchNpmTarballBytes (fetch-archive.ts is shared infra and stays); use the packument URL in the publishing tool. | -| 46 | F38 | signature handling diverges; depscan signer seam and signature columns are dead | both | dead-code | depscan:workspaces/patches/src/repack/sign.ts (defaultSign → null); repack-utils.ts:1333-1370 keeps RECORD.jws; crates/socket-patch-core/src/vendor/pypi_wheel.rs:570-585 | 110 | 0 | L | no | Strip RECORD.jws/.p7s in depscan; delete the sign seam; stop writing package_signature. Leave CLI maven alone (frozen). | -| 47 | F34 | every stored object is streamed back in full after upload | ds | expensive-abstraction | depscan:workspaces/patches/src/services/patch-package/build.ts:209,456; gcs-store.ts:108-117 (no checksum header) | 150 | 0 | L | no | Send md5/crc32c (md5 is already computed at build.ts:315,532) and read back only on a 412 collision. The berry and reset parts are in F33/F39. | -| 48 | F43 | public core fns with zero callers survive because rustc exempts pub | sp | dead-code | on integration f8b8d80a: crates/socket-patch-core/src/vendor/bun_lock.rs:89; vlt_lock.rs:1441; lock_inventory/view.rs:57,219,264 | 55 | 0 | L | no | Delete the 5 zero-caller fns and DirEntryInfo; move test-only helpers under cfg(test); add `#![warn(unreachable_pub)]`. | -| 49 | F48 | module-wide `#[allow(dead_code)]` on vlt_lock_text masks a dead method | sp | dead-code | crates/socket-patch-core/src/vendor/mod.rs:102; vlt_lock_text.rs:782 | 7 | 0 | none | no | Remove the allow; delete EdgeEntry::entry_text; use `cfg_attr` on find_node_dirs_sync. | -| 50 | F15 | setup leftovers: frozen hook wheel and Bundler plugin source, plus SetupConfig | sp | dead-code | pypi/socket-patch-hook, gem/socket-patch-bundler (1,053); crates/socket-patch-core/src/manifest/schema.rs:39-60 (43 `setup: None`) | 1,100 (70 new) | 0 | L | yes, WS7 (1,030) | Owner confirms, then delete both dirs; replace the initializers with `..Default::default()`. | -| 51 | F40 | setup-matrix (9 docker legs) is continue-on-error and tests `setup` | sp | ci-matrix | ci.yml:1634-1700; run 36359489402: 50.9 + e2e setup rows | 70 YAML | 56 | none | yes, WS7 (#279, already on integration) | Land WS7. | -| 52 | F17 | napi addon + hosted-bundle have 0 consumers; parity upkeep in 3 PRs | sp | high-cost-low-value | crates/socket-patch-cli/src/hosted_memory (4,546); crates/socket-patch-cli/src/commands/hosted_bundle.rs; ci.yml:77-105 node-addon 2m34s | 0 counted (750 claimed; parity retirement refuted, D4) | 1 | L | WS4 (owner keeps both engines) | After #280 lands and #282 is rebased onto it (F26), make no more hosted edits outside core/hosted. Run node-addon and parity only on `core/hosted/**` PRs until depscan adopts (F01). | -| 53 | F45 | publish dry run re-extracts the file map and re-unpacks upstream to disk to list names (no re-download) | ds | repacking | depscan:workspaces/patches/src/api/commands/review/validate-upstream-anchors.ts:118,178-190; publish.ts:1437-1454 | 30 | 0 | L | no | Fold into F61: convertPatchToPackage returns the entry order; drop the re-unpack. | -| 54 | F61 | one publish downloads upstream up to 3× and repacks twice | ds | repacking | validate-upstream-anchors.ts:74-86 (build discarded); depscan:workspaces/patches/src/services/patch-package/converter.ts:444-454; certify.ts:200-213,351 | 0 | 0 | L-M | no | Stage the dry-run archive by (purl, upstream digest) and let the converter adopt it after a digest re-verify, or cache verified upstream bytes by digest. | -| 55 | F59 | after WS1, vex refetches every record per run | sp | redundant-network | origin/v5/ledger-free-hosted crates/socket-patch-cli/src/commands/vex_sources.rs:888-960 (fetch_patch per uuid :930, fresh client :911) | 0 | 0 | L | partial (WS1/WS6) | Pass fetched records through WS6 ProjectContext, or add an immutable per-uuid on-disk cache (honouring `--offline`). Otherwise each vex run pays about +N views. | -| 56 | F71 | qualifier-less pypi patches: the CLI downloads the served sdist before rejecting it | both | redundant-network | crates/socket-patch-core/src/vendor/pypi.rs:1015-1041,1918-1926; crates/socket-patch-core/src/api/client.rs:1302-1308; depscan:workspaces/patches-shared/src/archive/ecosystem-archive-format.ts:146-165 | 0 | 0 | L | no | Decide from the step-1 artifact filename before the GET; server exposes artifact kind. | -| 57 | F70 | same waste seen from the vendored download path (one fix with F71) | sp | redundant-network | client.rs:1627-1631,1723 (256 MiB cap); crates/socket-patch-core/src/vendor/pypi.rs:1920,2040 | 0 | 0 | L | no | Same change as F71; add one shared sdist-served pypi golden. | -| 58 | F80 | auto mode eagerly fetches pristine upstream for uninstalled packages (only cargo defers) | sp | redundant-network | crates/socket-patch-cli/src/commands/vendor.rs:1838-1913 | −15 | 0 | L-M | no | Generalize the `cargo_via_service` deferral (PackageSource::Deferred) to every service-backed ecosystem. Superseded if repacking-to-depscan.md Phase 4 lands; the Deferred arm is deleted there (step 27). | -| 59 | F60 | hosted scan downloads each patched wheel in full to read METADATA | both | redundant-network | crates/socket-patch-cli/src/commands/scan/hosted.rs:1974-2096; crates/socket-patch-core/src/vendor/pypi.rs:89-127 | 0 | 0 | M | no | depscan persists PEP 658 metadata + hash and returns them from /patches/package; the CLI uses them and falls back to the download. | -| 60 | F66 | converter reads patched blobs one at a time | ds | other | depscan:workspaces/patches/src/repack/convert-patch.ts:140-185 | 0 | 0 | L | no | Bounded concurrency (~16), start the upstream download first; the dry-run adapter should honour abortSignal (validate-upstream-anchors.ts:323-327). | -| 61 | F69 | pypi bz2/xz sdists are selected, downloaded (≤256 MiB), then refused | ds | high-cost-low-value | depscan:workspaces/patches/src/repack/upstream/pypi.ts:152-168; repackers/pypi.ts:131-138; repack-utils.ts:771-797 | 0 | 0 | L | no | Reject non-.tar.gz/.zip sdists in the selector before downloading; add an xz arm. No CLI change. | -| 62 | F67 | disk stager treats diff-archive presence as full coverage; created files fail after default `repair` | sp | other (latent bug) | crates/socket-patch-cli/src/commands/fetch_stage.rs:212-235,316-320; crates/socket-patch-cli/src/commands/apply.rs:236,281; depscan generate-patch-diff-archive-task.ts:84-92 | 0 | 0 | L | no | Plausible, not reproduced. Make `repair` default to file mode, or require blobs for files with an empty before_hash; add a created-file test. | -| 63 | F50 | next depscan bump fails golden.test.ts on the 68 new vlt cases | both | cross-repo-dup | depscan:workspaces/app/src/patches/registry-rewrite/golden.test.ts:50-60; crates/socket-patch-core/tests/redirect_golden.rs:22-37 | 0 | 0 | L | no | Add a per-flavor TS_IMPLEMENTED allow-list mirroring RUST_IMPLEMENTED; do not port vlt to TS. | -| 64 | F77 | one red base test skips the e2e tier on all v5 PRs | sp | ci-matrix | crates/socket-patch-cli/tests/e2e_redirect_cargo_build.rs:829; ci.yml:676 `needs: test` | 0 | one-off (~3,100 spent) | L | no | Fix or quarantine case (3) and decide offline-vex-without-ledger semantics in WS1; rebase #279–#283. Do first. | -| 65 | F78 | in-flight v5 PRs: 344 runs, 34% cancelled or failed; #280 3.75 h without a CI verdict | sp | ci-matrix | ci.yml:22-24; run 36371317869 cancelled at 22 min after 303 job-min | 0 | ~200 per draft push (transient) | L | no | For drafts, run heavy CI and compatibility workflows on ready_for_review, a label or dispatch; put cheap gating jobs first. | -| 66 | F63 | five drafts cut in parallel from one base on the same hot files | sp | ci-matrix | merge-base 8ae7dc37 for all; crates/socket-patch-cli/src/commands/get.rs and tests/covgap_commands_rollback.rs touched by all 5 | 0 | ⊂ F78 | L | no | Rebase serially (WS1 → WS3 → WS4 → WS5 → WS7/8); skip compatibility workflows on drafts. | -| 67 | F26 | #282 moves the hosted ledger into core while #280 deletes it | sp | other | origin/v5/one-hosted-engine crates/socket-patch-core/src/hosted/ledger.rs (311); merge-tree: 10 conflicts | 0 terminal (311 churn) | 0 | L | partial (WS4 depends on WS1) | Land #280 first, rebase #282, drop core/hosted/ledger.rs except the migration-only reader. | -| 68 | F44 | #279 WS8 edits hosted text and tests that #280 deletes and #282 moves | sp | other | #279 469a6711/f200524f; core/hosted/guidance.rs:46-107 on #282 still says "redirect" | 0 terminal (30 churn) | 0 | L | WS8 | Apply the WS8 hosted wording after #282, in core/hosted/guidance.rs. | -| 69 | F05 | two builders per archive-shaped artifact produce different bytes; reuse.rs hides the flip | both | repacking | crates/socket-patch-core/src/vendor/npm_pack.rs:21-43 vs depscan:workspaces/patches-shared/src/archive/repack-utils.ts:597-660; crates/socket-patch-core/src/vendor/reuse.rs:1-12 | 0 counted (3,300 if rebuild dropped) | 0 | M | WS5 caveat; #283 keeps rebuild | The owner keeps the local rebuild (WS5; blockers in F72). The only actionable part is aligning the npm recipe (upstream order, mtime 0) so both builders produce the same bytes and reuse.rs shrinks; this stays useful while WS5 keeps the rebuild. See repacking-to-depscan.md for the gated deletion path (gross ~2,050 src / ~1,260 test, net ≈ −1,150 src after ~900 src / ~900 test of additions). | - -## Measurements and checked-not-waste - -These are kept as facts. They are not ranked and their LOC is not counted as -net-new. - -| id | what it established | use | -|----|---------------------|-----| -| F08 | WS1 test surface: 80 test files and 326 refs to redirect-state; about 2.2k LOC of ledger-only tests | Within WS1: delete ledger-only corrupt/replay tests instead of porting them; keep tests for the legacy-read migration (v5-plan.md:47). | -| F31 | hosted.rs ↔ hosted_memory still share 161 verbatim lines on integration; only #282 removes them | Counted inside WS4 (#282). | -| F42 | Deprecated aliases, tool_command and the CI old-path grep are already deleted on integration | Done; list them as breaking changes in the v5 notes. | -| F62 | bun.lockb writer and vex/discover reuse the shared codecs | Not waste; WS3 `wired_refs()` absorbs the glue. | -| F64 | Per-PR deletion ledger (see Totals) | Use it for the de-duplication below. | -| F65 | #283 keeps the local rebuild and resolves repair/service | The #283 plan note is the WS5-caveat answer. | -| F68 | The diff archive and the repacked package serve different modes | Assess the diff channel against blobs, never against repacking. | -| F72 | Server fail-closed classes make the local rebuild the only vendoring path for them (pypi qualifier-less/wheel-only, locally pinned wheels and tarballs, bzip2 sdists) | Blocks F05; verification removed gem platform and go no-go.mod as blockers. | -| F75 | depscan repack tests are 0.4% of Tap Unit and 0.9% of Tap Integration time | Do not cut repack tests; patches Tap cost is orchestration and backtests. | -| F76 | Map corrections: repack 6,015 src / 4,976 test (111 `tap.test` + 22 `t.test`); berry_zip.rs 333 src; reuse.rs 382 src; purl-api-proxy path | Figures used here. | -| F79 | Bump depscan's gitlink in three steps (base tip, then integration, then past #280), pre-flighting each SHA | Sequencing for F11, F27 and F50. | - -## Top-10 cuts - -| # | id | cut | code | test | docs/YAML | CI job-min/run | -|---|----|-----|-----:|-----:|----------:|---------------:| -| 1 | F51 | e2e build-once fan-out | 0 | 0 | 0 | 280 (ci.yml) | -| 2 | F03 | delete #257 oracles after snapshotting inputs | 0 | 6,500 | 0 | 0.5 | -| 3 | F02 | delete depscan refactor docs except DAG/ | 0 | 0 | 8,222 | 0 | -| 4 | F41 | drop per-push e2e-docker | 0 | 0 | 65 | 65 (ci.yml) | -| 5 | F04 | one test suite per command | 0 | 4,000 | 0 | ⊂ F58 | -| 6 | F53 | build Dockerfile.base once | 0 | 0 | 0 | ≈35 after F41 (ci.yml) | -| 7 | F55 | pdm capstone build-once + dedupe | 0 | 0 | 0 | 65 (pdm-compat) | -| 8 | F52 | tier middle PM versions off PRs | 0 | 0 | 0 | ≈40 after F51 (ci.yml, PR only) | -| 9 | F06 | retire depscan legacy engine (incl. F19) | 2,750 | 250 | 0 | 0 | -| 10 | F01 | depscan calls the Rust engine; delete TS twin (gated) | 5,000 (gated) | 5,500 (gated) | 0 | 1 (depscan) | -| | | **total** | **7,750** | **16,250** | **8,287** | **≈420 ci.yml per PR run (≈380 main push) + 65 pdm-compat + 1 depscan (F01, gated)** | - -32.3k lines in all, including the gated F01 (10.5k); 21.8k actionable now. - -## Totals - -### Net-new savings (not in v5-plan or PRs #279–#283) - -| bucket | (a) code | (b) test | (c) docs/non-code | total | -|--------|---------:|---------:|------------------:|------:| -| Actionable now | 9,137 | 14,925 | 8,752 | 32,814 | -| Gated (F01 adoption, F07 capture contract, F14 diff-mode decision, F18 backlog drain, F22 telemetry decision) | 6,275 | 9,395 | 0 | 15,670 | -| **Net-new total** | **15,412** | **24,320** | **8,752** | **48,484** | - -- Code (a): F06 2,750, F09 1,600, F12 1,200, F16 900, F20 360, F25 320, - F24 280, F32 220, F21 150, F28 150, F30 150, F34 150, F27 140, F33 100, - F39 100, F36/F37/F38 110 each, F15 (SetupConfig part) 70, F29 90, F43 55, - F45 30, F48 7, F80 −15. Gated: F01 5,000, F14 565, F22 450, F18 260. -- Test (b): F03 6,500, F04 4,000, F10 1,400, F11 1,380, F21 300, F06 250, - F20 200, F29 170, F27 160, F28 150, F24 145, F35 120, F30 100, F33 50. - Gated: F01 5,500, F07 2,900 (Python harness), F18 430, F14 565. -- Docs and non-code (c): F02 8,222 (depscan refactor docs), F23 440 (depscan - deploy YAML), F41 65, F46 13, F47 10, F49 2 (ci.yml). -- (d) CI job-min per run, de-duplicated: - - socket-patch `ci.yml`: F51 280, F41 65, F52 ≈40 (after F51, PR only), - F53 ≈35 (after F41), F47 ≈23 (after F51), F49+F58 ≈30 combined, F46 ≈3 - (after F51), F17 1, F03 0.5, F10 0.3. Total **≈478 per PR run, ≈438 per - main push**, against 945 for main push 36359489402. The standalone sum - is about 585 (F52 at ≈90); the difference is the overlaps below. - - Compatibility workflows, per triggered PR push: F55 65, F57 12, F56 ≈10 - (install-proof dedupe beyond F51), F54 8. About **95**. - - depscan, actionable: F73 7.5 + F11 2 ≈ **9.5 per api-v0 CI run** (~130 - runs/day). Gated: F01 1, F14 0.5, F18 0.3 (Tap unit/integration, not - api-v0). F07 adds 30 per pdm/hatch trigger (F74's 15 is its interim - subset). - - Transient, during the v5 train only: F78 about 200 per draft push. F78 - uses the savings verification's ≈200 rather than the recorded 250 - (compatibility workflows are path-filtered). F63's recorded 475 is an - upper bound on the same cancelled runs and is not counted. F77: about - 3,100 job-min already spent on runs whose result was known in advance. - -### Overlaps not double counted - -- F19 ⊂ F06 (same file); F74 ⊂ F07; F70 = F71 (one fix); F63 ⊂ F78; - F45 ⊂ F61's change. -- F13 is the alternative to F01: its TS half is inside F01's 5.5k test LOC. - It is excluded. -- F17's 750 is excluded because hosted_memory_parity retirement was refuted - (D4); only its CI gating (1) counts. F31 is WS4. -- F56's ci.yml half (≈50 of 60) is inside F51. F52 and F46 shrink once F51 - cuts leg cost from about 3.0 to about 1.2 min. -- F47's 3 e2e_safety rows are F51 legs (11.1 job-min at full cost); after - F51 they save ≈4, so F47 ≈23 is counted, not 30. -- F53 after F41 keeps only coverage-docker's builder stage; its setup-matrix - share is WS7. -- F49, F58 and F04 overlap (fewer binaries and one compile), so ≈30 is - counted, not 43. -- F11 carries the depscan setup test deletion; F40 and F73 mention the same - 59 file and are not counted again. -- F27 carries the depscan ledger change; F11(e) is the same item. -- F26 and F44 are churn avoided (0 terminal LOC). -- F05 (3,300) is excluded: the owner keeps the rebuild, and F72 lists the - blockers. -- Residual risk of double counting: F10 vs F04 (≤0.7k of e2e/in_process - CRLF tests); F04 vs F08 (ledger tests inside covgap files, which WS1 owns). - -### Already planned (context, not counted) - -Per-PR ledger (F64, verified; `git diff --shortstat 8ae7dc37`): - -| branch | + / − | net | note | -|--------|-------|----:|------| -| #279 remove-setup-and-ui (WS7/WS8) | +1,599 / −31,648 | −30,049 | setup removal | -| #280 ledger-free-hosted (WS1) @08c30b7e | +21,968 / −21,268 | +700 | adds upstream/* 8.4k (see F16); at 65aa0744: +23,055 / −21,269, net +1,786; upstream/* 8,752 | -| #281 lock-models (WS3) @85421f3b | +4,495 / −3,353 | +1,142 | | -| #282 one-hosted-engine (WS4) | +5,209 / −4,634 | +575 | ports ledger into core (F26) | -| #283 vendor-backend (WS5) | +2,776 / −6,325 | −3,549 | keeps local rebuild | -| v5/integration (#279+#281+#283) | +7,974 / −40,841 | −32,867 | tests 9,256 → 8,589 | - -- Setup removal is 77.5% of integration's gross deletions and about 91% of - its net. WS1, WS3 and WS4 are net additions until F16 and F26 are folded - in. Report v5 savings from integration totals, never per PR. -- Findings that fall inside this planned work: F08 (2.2k WS1 tests), F15 - (1,030 of 1,100, WS7), F31 (WS4), F40 (70 YAML, 56 job-min, WS7), F42 - (follow-ups, done). Also excluded: F04's covgap_setup* (2,717), F58's ~21 - setup binaries, F10's core/setup CRLF tests, and F53's setup-matrix image - builds. -- Extends-plan items are counted as net-new because the plan does not name - their deletions: F09, F10, F16, F25 (WS3); F12, F32 (WS3/WS5); F21, F29 - (WS8); F46 (follow-ups); F27, F59 (WS1/WS6 counterparts); F17 (WS4 - sequencing). - -## Repacking summary - -Full treatment: [repacking-to-depscan.md](repacking-to-depscan.md). -- depscan builds every served artifact asynchronously after publish: - `published_patches` is the queue, patch-package-converter does the build, - and outputs are write-once GCS objects. Only registry metadata is - assembled per request. depscan repack is 6,015 src / 4,976 test LOC. -- The CLI's local builders are about 2.8k src (npm_pack, berry_zip, - pypi_wheel, reuse, part of registry_fetch; F05 correction). They are the - `auto` fallback, `build`, `--offline` and dry-run path. The 9-file map - total of 6,515 src / 7,780 test includes golang_local.rs and prestage.rs, - which are not the local build. Of the local build, - repacking-to-depscan.md deletes ~2,050 src / ~1,260 test if the WS5 - caveat is reversed; pypi_wheel (the one local class), berry_zip (the - verifier and WS1), the verifiers and maven/nuget stay. -- The two builders' bytes differ for every archive-shaped ecosystem (F05). - #283 keeps the rebuild; F72 lists the classes only it can vendor. -- Waste on the server: F61 and F45 (publish re-downloads and repacks), F66 - (serial blob reads), F69 (bz2/xz after download), F33/F34/F38/F39 - (sidecars, read-back, sign seam, reset paths), F36 (second npm fetcher). -- Waste in the CLI: F70/F71 (discarded sdist downloads), F80 (eager - pristine fetch), F28 (per-uuid reference POSTs). -- Shared: F35 (10c0 twins, fixtures only). -- Not waste: repack test time (F75); diff vs repack (F68). -- The service-hit vs local-fallback rate is still unmeasured. CLI telemetry - does not record vendor-source fallback. Any decision to drop the rebuild - needs that number first (see Caveats). - -## Dropped findings (refuted; do not re-raise) - -| # | finding | refuted because | -|---|---------|-----------------| -| D1 | Two lockfile patch-reference recognizers with unequal fixture corpora | Both are needed: the offline fail-closed CLI and the server SBOM resolve. Nothing is removable (0 LOC). | -| D2 | Go hosted pin implemented three times | False: the CLI has one go.sum writer; rewrite_golang calls go_sum_edit (redirect/mod.rs:7160). | -| D3 | #280 carries dead takeover.rs/replay.rs/client.rs.orig | Stale snapshot: the #280 head already deleted them (9b0f61b8). | -| D4 | hosted_memory_parity becomes a self-comparison after WS4 | False: the memory side keeps its own discovery, roots and selection front end; savings overstated ~10×. | -| D5 | vlt scenarios tested up to 4 times | Not duplicates: synthetic in-process trees vs real-installer e2e; deletion would drop unique coverage. | -| D6 | depscan api-v0 e2e retests CLI internals; vendor suites never hit the server | False: 89–94 seed real patches and download through live api-v0. | -| D7 | Test LOC concentrated in low-churn code; lock_inventory barely tested | Measurement error (test-only files counted as src); 0 savings. | -| D8 | depscan repack operator CLIs are dead | Manual operator tools, not dead code. | -| D9 | CLI fetches full patch views instead of metadata/batch records | Most call sites reuse the full view for the download; the fix adds code (a new client method and proxy route) and removes none. | -| D10 | Vendored staging downloads blobs before asking the service | False for scan/get: they seed blobs from the records download; the fix needs an endpoint the client lacks. | -| D11 | vlt preflight downloads every hosted tarball each scan | The bodies feed heal and stale detection; the fix adds code; 0 savings. | -| D12 | Telemetry builds a new HTTPS client per event | Each command sends once; negligible savings. | -| D13 | scan/vex/vendor re-crawl in separate processes | By design (VEX attests current disk bytes); `scan --vex` already reuses the crawl; 0 savings. | -| D14 | Self-evolving harness: 10.3k LOC plus 2×1 TiB Filestore | Infra is gated per env (prod disabled); the cost claim is wrong. | -| D15 | Maven/NuGet vendoring costs 13k LOC and ~87 job-min | Most of it is hosted maven/nuget (not frozen; WS1 extends it) or setup (WS7). | -| D16 | ledger_snapshots v2 schema is waste | The proposed redesign is the one reverted for data loss (5c173d6c); net savings ≈0. | -| D17 | Self-update subsystem is high-cost/low-value | Standalone install is the headline channel (Windows needs it); 0 savings proposed. | -| D18 | WS1 makes berry_zip/registry_fetch load-bearing | Already load-bearing across vendored paths; the recommendation moves code, it deletes none. | -| D19 | Default diff mode always downloads blobs; delete the bsdiff channel | The default `repair` writes diff-only sources that later apply from, so the channel does save bytes (see F14, F67). | -| D20 | Size/entry caps differ between the server and CLI fetchers | Mostly false (the CLI is more permissive on served artifacts); not waste. | -| D21 | depscan upstream fetchers have no fetch/verify tests | False: 8 live repack-checksum e2e suites (3,219 LOC); it is a coverage gap, not waste. | -| D22 | Missing-digest policy differs (composer/old npm) | Not waste; misreads when the CLI composer fetch runs. | -| D23 | Sidecar md5 computed for every artifact but served only to maven | Negligible (~15 LOC); misreads the maven freeze. | -| D24 | Service-hit vs fallback rate unobservable | Service side is observable (patchServer.downloads); the fix adds code. The data gap is kept as a caveat. | -| D25 | Build-state gauges lack an ecosystem label | Per-ecosystem failure counters already exist; the fix adds code. | -| D26 | depscan "patches - Installer E2E" path filter too broad | A safe filter must keep imported lib/app/pipeline paths; savings fall below the bar. | - -## Caveats - -- **History.** socket-patch history starts at 2025-11-10 (51ea2850). Churn - and fix-commit counts cover about 10.5 months, and subject-only vs - body-matching `--grep=fix` counts differ; the verification notes say - which. depscan - counts use `--follow` where files moved. -- **Moving branches.** #280 and #281 moved during the review (#280 f1cc47bb - → 08c30b7e → dc634b31 → 65aa0744). F16, F26, F44 and F59 cite branch heads and need a - re-check before acting. -- **Line numbers.** They are against release/v5-prerelease 8ae7dc37 unless - marked integration (f8b8d80a) or branch. ci.yml lines differ by about 22 - between the two. -- **socket-patch CI minutes.** Job-minutes from the Actions job API: main - push 36359489402 (246 jobs, 944.9 job-min) and PR runs 36363939533, - 36363939563, 36368399706, 36362334985. They are job-minutes, not wall-clock - and not billed minutes (macOS bills 10×, Windows 2×). Some logs were read - only from the 5,000-line tail, so compile shares were sampled. Numbers - "after Fnn" are derived, not measured. -- **depscan CI minutes.** An early estimate came from - localdev/tap/test-durations.json and was corrected by measuring 7 runs - (F75). Deploy and pdm/hatch runs report 0 billable ms (non-billed runners), - so their totals come from per-job durations. -- **Production data.** None of it was queried. Grafana SQL and gateway logs - are needed for F18 (backlog count), F20 (purl-api /patch traffic), F33 - (.berry.zip fetches), F71 (bare-purl pypi share), F14 (diff-route - telemetry), and the service-hit vs local-fallback rate that any - local-rebuild decision needs. -- **Not measured.** The full cost of a depscan submodule bump was not run - end to end (F11 is grep-based; its vendor suites 89–94 were not run - against integration). F67 is plausible but not reproduced. -- **Savings.** They assume the recommended change, not deletion by default. - Savings lens refuted but 2 of 3 upheld: F13, F17, F28, F34–F39, F43, F45, - F48, F80 (figures are the corrected ones, or 0 where the correction says - nothing is removable). Value lens refuted but 2 of 3 upheld: F05, F10, - F14, F18, F23, F24, F25, F27, F63, F78. The 0-LOC ranked findings F44, - F50, F59–F61, F66, F67, F69–F71 and F77 also had the savings lens refuted - and count nothing. The rank column does not show votes; this list does. diff --git a/docs/development.md b/docs/development.md new file mode 100644 index 000000000..1dcb3e88f --- /dev/null +++ b/docs/development.md @@ -0,0 +1,98 @@ +# Development + +Socket Patch discovers dependency versions, selects available Socket patches, and +makes those patches consumable through hosted references, committed artifacts, or +in-place application. The [README](../README.md) describes the user workflow; the +[CLI contract](../crates/socket-patch-cli/CLI_CONTRACT.md) specifies public behavior. + +## Build + +Use Rust's stable toolchain and Cargo from the repository root: + +```sh +cargo build --locked -p socket-patch-cli +./target/debug/socket-patch --help +``` + +`Cargo.toml` is the source of the binary's version. The v5 prerelease branch can +still carry the previous version until the release bump; use a binary built from +this checkout when verifying branch behavior. + +The workspace's `.cargo/config.toml` disables persisted Socket login and passive +update checks for Cargo runs. This keeps tests independent of a developer's account. +Override `SOCKET_NO_CONFIG=0` explicitly when a manual `cargo run` should use the +persisted login. + +## Code map + +| Component | Responsibility | +| --- | --- | +| [`socket-patch-cli`](../crates/socket-patch-cli/src/) | Arguments, command orchestration, terminal output, and JSON responses | +| [`socket-patch-core`](../crates/socket-patch-core/src/) | API access, discovery, selection policy, patching, format handling, vendoring, and VEX | +| [`socket-patch-node`](../crates/socket-patch-node/) | Node bindings for the in-memory hosted engine | +| [`scripts/`](../scripts/) | Installers, release tooling, compatibility runners, and performance tools | +| [`tests/docker/`](../tests/docker/README.md) | Container fixtures for native package-manager integration tests | + +Within core, start with `crawlers/` and `vendor/lock_inventory/` for package +inventory, `formats/` for shared format models, `api/ranking.rs` for patch ranking, +`policy/` and `rollout/` for selection, `hosted/` for the hosted engine, +`patch/redirect/` for dependency rewrites and upstream restoration, `vendor/` for +artifact backends, and `vex/` for attestation. + +### State and command boundaries + +- **Hosted state** is derived from dependency files. The lockfiles and related + manifests/configs identify the patch and the source the package manager consumes. + The CLI fetches patch metadata as needed; it writes no hosted ledger. +- **Vendored state** pairs `.socket/vendor/state.json` with its artifacts. Entries + carry patch records, fingerprints, and reversible edits. A ledger is required for + repair and managed reversal; discovering a reference is not enough to rebuild it. +- **Agent state** uses `.socket/manifest.json` and patch data. Agent commands apply + and verify file-level changes against installed packages. +- **Legacy hosted records** can supplement metadata while migrating old projects. + They do not prove a patch is still wired into the project. + +CLI commands share [`ProjectContext`](../crates/socket-patch-cli/src/commands/context.rs) +for lazy ledger, inventory, and reference discovery. Its disk snapshot gives readers +the same file contents. Writers reload mutable state under the apply lock; embedded +VEX reloads the result after writes. Vendored commands share +[`VendoredBackend`](../crates/socket-patch-cli/src/commands/vendored_backend/). +The in-memory hosted engine operates on supplied files, and parity tests compare +its results with the disk path. + +Keep these boundaries when extending the project: + +- A repository policy can narrow or pace selection, but cannot set credentials, + endpoints, or bypass safety checks. See [configuration](configuration.md). +- Presence in a manifest or ledger is separate from whether the package manager + consumes a patch. VEX checks live references and available evidence. +- Preserve unrelated dependency-file edits. Refuse unsupported formats or unsafe + drift instead of claiming a patch is applied. +- Test the files and bytes the native installer consumes, including fresh checkouts + and relevant warm caches. A successful rewrite alone does not prove delivery. + +## Validation + +Choose checks for the affected behavior: + +```sh +cargo test --locked -p socket-patch-core --lib +cargo test --locked -p socket-patch-cli --test cli_parse_scan --test cli_parse_get +python3 -B -m unittest discover -s scripts/tests -v +cargo clippy --workspace --all-features -- -D warnings +``` + +The parser suites cover the public CLI. Core unit tests and committed fixtures cover +format handling. Integration suites cover lifecycle, failures, and native installers; +see the [testing guide](testing/README.md) for toolchains and opt-in network tests. +Update relevant contract entries and tests when changing flags, defaults, output, +exit codes, or supported formats. + +Compatibility tables describe support boundaries and reproducible checks. In +particular, the vlt tables and `vlt-coverage.json` are inputs to validation scripts: +keep them in sync with tests and workflows. Store individual experiment logs and +full backtest results as run artifacts, not as new product documentation. + +For performance work, use the [record/replay harness](../scripts/perf/README.md). +For publishing, follow the [release runbook](releasing.md) and +[installer hosting guide](installer-hosting.md). diff --git a/docs/ecosystems.md b/docs/ecosystems.md index f94ed82be..a90488668 100644 --- a/docs/ecosystems.md +++ b/docs/ecosystems.md @@ -1,11 +1,11 @@ # Ecosystem & platform support This is the detailed support matrix for `socket-patch`: which package ecosystems work -with which [patch mode](../README.md#three-patch-modes), the per-ecosystem caveats, and +with which [patch mode](../README.md#patch-modes), the per-ecosystem caveats, and the platforms the binary ships for. For what the three modes *are* and how to choose between them, see -[How Socket Patch works](../README.md#how-socket-patch-works) in the README. +[Patch modes](../README.md#patch-modes) in the README. ## Mode × ecosystem matrix @@ -18,7 +18,7 @@ The backticked slug in each row is the value `-e`/`--ecosystems` accepts (e.g. | PyPI (`pypi`) — uv / poetry / pdm / pipenv / pip | ✅ in place | ✅ uv project/script locks, PEP 751 `pylock.toml` / `pylock..toml`, poetry, pdm, pipenv (Pipenv 2018 or later — every `Pipfile.lock` category is rewired, lock-only checkouts included; Pipenv 2023+ does not hash-check local wheels — `vendor_integrity_unverified`; a venv still holding the upstream release is reported as `pypi_pipenv_stale_install`; see [Pipenv compatibility](testing/pipenv-compatibility.md)), and requirements.txt. Native uv vendoring requires uv ≥ 0.2.35 (the `[[package]]` lock grammar); hosted mode covers native `uv.lock` from uv 0.1.45 (the first release whose `uv lock` writes one) and requirements from uv 0.0.5; see [uv compatibility](testing/uv-compatibility.md). | ✅ requirements.txt including hash continuations, uv project/script locks, and PEP 751 locks. Version/source ambiguity is refused; see [uv compatibility](testing/uv-compatibility.md). Poetry 1.x and 2.x locks are supported; Poetry 0.x ignores URL sources and is refused. See [Poetry compatibility](testing/poetry-compatibility.md). Pipenv `Pipfile.lock` (pipfile-spec 6 — Pipenv 7 and later; `path` references for 7–11, `file` from 2018; lock-only checkouts and Pipenv's out-of-tree venv are discovered; a warm venv that Pipenv will not reinstall over warns `redirect_pypi_stale_install`; see [Pipenv compatibility](testing/pipenv-compatibility.md)). `pdm.lock` is supported for the lock formats PDM 0.12–1.4 and 2.8.1+ write (`lock_version` 2 / 4.3–4.5.1); the identity-losing 3.1 / 4.0–4.2 formats (PDM 1.8–2.7) are refused. PDM 2.8.0 writes an indistinguishable `4.3` lock but shares that identity-loss bug, so a rewritten 2.8.0 lock crashes `pdm sync` — upgrade to ≥ 2.8.1. See [PDM compatibility](testing/pdm-compatibility.md). | | Cargo (`cargo`) | ✅ in-place + `.cargo-checksum.json` rewrite (shared registry-cache caveat — see [Cargo: shared registry cache](#cargo-shared-registry-cache)) | ✅ `[patch.crates-io]` path entry in the root `Cargo.toml` (v5; per-version Socket keys; pre-v5 `.cargo/config*` wiring migrates on re-run) | ✅ per-patch sparse registry (`[registries.socket-patch-]` + Cargo.lock source/checksum); direct dependencies only — a crate another dependency also pulls in is refused, use `--mode vendored`; with no `Cargo.lock` the graph is unknown, so only a project whose sole dependency is the patched crate is redirected | | RubyGems (`gem`) | ✅ in place | ✅ Gemfile + Gemfile.lock path pair (`Gemfile` spelling only — a `gems.rb` project cannot vendor yet) | ✅ per-dep `source` block — edits `gems.rb` + `gems.locked` when present (bundler prefers them over `Gemfile`; spellings that diverge beyond Socket's own edits fail closed with `redirect_gem_gemfile_spellings_diverge`); the `CHECKSUMS` pin needs bundler ≥ 2.6 (older locks get a `redirect_gem_no_checksums_section` warning); a stale pre-redirect materialization that `bundle install` would reuse instead of refetching is flagged `redirect_gem_stale_install` with a prescriptive remedy (see CLI_CONTRACT.md's "Gem stale-install guard") | -| Go (`golang`) | ✅ `go.mod` `replace` → `.socket/go-patches/` — see [Go: directory replaces and go.sum](#go-directory-replaces-and-gosum) | ✅ `replace` → the committed vendor tree | ✅ (free tier) fork-style `replace` → `patch.socket.dev/gopatch/` + committed `go.sum` pin; see [golang-hosted.md](design/golang-hosted.md). Paid tier stays ❌ ([golang-hosted-no-go.md](design/golang-hosted-no-go.md)); `redirect_golang_unsupported` names the vendored remedy | +| Go (`golang`) | ✅ `go.mod` `replace` → `.socket/go-patches/` — see [Go: directory replaces and go.sum](#go-directory-replaces-and-gosum) | ✅ `replace` → the committed vendor tree | ✅ (free tier) fork-style `replace` → `patch.socket.dev/gopatch/` + committed `go.sum` pin; see [Go notes](#go-directory-replaces-and-gosum). Paid hosted patches are unsupported; `redirect_golang_unsupported` names the vendored remedy | | Maven (`maven`) | ✅ in-place jar patching leaves the `~/.m2` checksum sidecars stale — prefer vendored / hosted, see [Maven & NuGet caveats](#maven--nuget-caveats) | ✅ committed maven2 `file://` repository. A root pom declaring `` (multi-module aggregator) is refused (`vendor_maven_multimodule_unsupported`), and a gradle-only project is refused (`vendor_gradle_unsupported`) | ✅ **pom projects only, fail-closed** — the patched jar is pinned at a Socket-only `-socket.` suffix; `${property}` versions are refused; Gradle gets a manual `exclusiveContent` snippet — see [Maven & NuGet caveats](#maven--nuget-caveats) | | NuGet (`nuget`) | ✅ in-place patching deletes `.nupkg.metadata` and advises on the `.nupkg.sha512` tamper-evidence sidecar — prefer vendored / hosted, see [Maven & NuGet caveats](#maven--nuget-caveats) | ✅ committed folder feed + `packageSourceMapping` + `packages.lock.json` contentHash pin | ✅ `nuget.config` source + source-mapping, `packages.lock.json` contentHash rewrite. See the locked-mode note in [Maven & NuGet caveats](#maven--nuget-caveats) | | Composer (`composer`) | ✅ in place (`vendor/`) | ✅ `composer.lock` `dist: path` rewrite | ✅ `composer.lock` dist url + shasum rewrite; the entry's `source` and `dist.mirrors` are removed. See [composer-compatibility.md](testing/composer-compatibility.md) | @@ -384,6 +384,14 @@ Honest limits of the Maven and NuGet flows — documented behavior, not bugs: client-side content pin (vendored surfaces this as a `vendor_nuget_no_lockfile` warning; the feed + source mapping still force the patched copy). +* **NuGet package signatures (local vendoring).** Rebuilding a `.nupkg` changes + its contents, so the local builder removes the upstream `.signature.p7s` rather + than retaining an invalid signature. Environments requiring signed packages need + a compatible signing policy or an appropriate service artifact; local vendoring + does not preserve the upstream author's signature. Service artifacts are copied + without local repacking. The current implementation uses a folder feed with + source mapping. + ## Cargo: shared registry cache Agent mode patches the crate in place wherever the crawler finds it. For a non-vendored @@ -523,17 +531,46 @@ commit it, and review it like any other vendored code. The wiring survives `go mod tidy`, and `apply --check` gives CI a read-only audit that the committed redirects still match the manifest. -Hosted mode uses Go's other native `replace` form — a fork-style -module-to-module directive onto a Socket-published, content-addressed module -(`replace => patch.socket.dev/gopatch/ -socketpatch.`) -plus the module's two committed `go.sum` lines. Because go consults the -checksum database only for modules *absent* from `go.sum`, the committed pair -is the complete day-2 state: fresh clones and CI build the patched module with -no machine-local configuration, and a tampered hash still fails closed with -go's checksum `SECURITY ERROR`. Free tier only; the paid-tier analysis (and -the ephemeral-CI workaround) is in -[golang-hosted-no-go.md](design/golang-hosted-no-go.md), the full free-tier -design in [golang-hosted.md](design/golang-hosted.md). +Hosted mode uses a fork-style module replacement and two committed checksums: + +```text +# go.mod +replace example.com/module v1.4.2 => patch.socket.dev/gopatch/ v1.4.2-socketpatch.1 + +# go.sum +patch.socket.dev/gopatch/ v1.4.2-socketpatch.1 h1: +patch.socket.dev/gopatch/ v1.4.2-socketpatch.1/go.mod h1: +``` + +The service supplies the replacement path, version, and both hashes; the example +version is illustrative. Both hashes must be present before the CLI writes the +replacement. Go uses committed `go.sum` entries without consulting the checksum +database for those entries, so a fresh checkout needs no per-machine checksum +exemption. A mismatched checksum still fails the build. The rewriter removes the +replaced version's original sum lines to keep the result stable under `go mod tidy`. + +This requires a free, publicly retrievable patch reference carrying a `goproxy` +override. CLI support does not imply a patch is published for a particular module. +Paid hosted Go references are unsupported: embedding credentials in module paths +would expose them to module proxies and change module identity. Use vendored mode +for those patches; the CLI reports `redirect_golang_unsupported` when the required +hosted reference is absent. + +Important limits: + +- A replacement targets an exact original module version. Updating the `require` + can leave it unused; re-scan and regenerate VEX after dependency updates. +- An internal `GOPROXY` must be able to serve or forward the Socket module path. + Comma-separated proxy fallbacks do not recover from every HTTP error. +- User-authored conflicting replacements are preserved and the patch is refused. + Missing module metadata, untrusted Socket module paths, or missing integrity + values are also refused before writing. +- Local directory replacements in agent and vendored mode are not checked against + `go.sum`; commit and review those trees. Hosted replacements use the module + checksum mechanism above. + +The implemented hosted shape and fresh-checkout behavior are exercised by +[`e2e_golang_hosted_build.rs`](../crates/socket-patch-cli/tests/e2e_golang_hosted_build.rs). ## Supported platforms diff --git a/docs/migrating-to-v5.md b/docs/migrating-to-v5.md new file mode 100644 index 000000000..e597b32d0 --- /dev/null +++ b/docs/migrating-to-v5.md @@ -0,0 +1,78 @@ +# Migrating to v5 + +v5 makes hosted patching the default workflow. Review these changes before running +existing scripts against the new CLI; the [changelog](../CHANGELOG.md) and +[CLI contract](../crates/socket-patch-cli/CLI_CONTRACT.md) cover the full release. + +## Defaults and stored state + +- Bare `scan` and `get` now patch in hosted mode. `scan` never prompts; + hosted and vendored `get` do not prompt either. Use `scan --dry-run` for a preview + or `--mode agent` to retain in-place patching. Global scans and a mode-less + `scan --prune` do not acquire new patches; `--prune` still performs cleanup. +- Hosted state lives in dependency files. No command writes + `.socket/vendor/redirect-state.json`. Legacy hosted records can still supply + metadata, but do not replace live references. +- Hosted `rollback` and `remove` reconstruct upstream registry entries and + generally need network access. They refuse unsupported restoration, including + binary `bun.lockb`, with a version-control recovery hint. +- `rollback` now removes patch records and unused artifacts as well as restoring + dependencies. Pass `--preserve-state` to retain local state for reuse. +- `scan` / `get --mode vendored` need no agent manifest. Commit + `.socket/vendor/state.json` with the artifacts. `repair` no longer reconstructs + a missing ledger from lockfiles. +- Vendored Cargo patches move into workspace-root `Cargo.toml` and use + `+socket.` versions. Re-running vendoring or repair migrates + older wiring. The tag is visible in `CARGO_PKG_VERSION`; see + [Cargo details](ecosystems.md#cargo-vendored-wiring-in-cargotoml). +- `list` succeeds on an empty project. Hosted results identify lockfiles instead + of a hosted ledger. Scripts must use the updated + [JSON shapes and exit codes](../crates/socket-patch-cli/CLI_CONTRACT.md#json-output-shapes). + +## Installation channels + +v5 distributes standalone binaries, Cargo crates, and npm packages. The PyPI and +RubyGems CLI distributions and the `socket-patch-hook` / `socket-patch-bundler` +helpers are no longer published. Python and Ruby projects remain supported. + +Remove the old CLI with the manager that installed it (`pip uninstall socket-patch`, +`pipx uninstall socket-patch`, or `gem uninstall socket-patch`). Install through a +[supported channel](../README.md#installation), update CI bootstrap commands, and +run `socket-patch --version` to check which binary your shell finds. + +## Retire `setup` hooks + +`socket-patch setup` is removed. Existing hooks may still call `apply`, but v5 no +longer creates or maintains them. + +To move an agent project to hosted mode, run `socket-patch rollback`, then +`socket-patch scan`, review and commit the changes, and reinstall dependencies. +To stay in agent mode, retain `.socket/` and explicitly run `socket-patch apply` +after dependency installs in CI. + +Remove only the Socket-managed portions of old hooks, preserving other commands: + +| Ecosystem | Cleanup | +| --- | --- | +| npm / pnpm / yarn / bun | Remove the Socket Patch `apply --silent --ecosystems npm` command from `package.json`'s `postinstall` and `dependencies` scripts; remove empty script keys | +| Composer | Remove `socket-patch apply --offline --silent --ecosystems composer` from `post-install-cmd` and `post-update-cmd` | +| Python | Remove `socket-patch[hook]` from requirements or project dependencies, and uninstall `socket-patch-hook` in affected environments | +| Bundler | Remove the managed `plugin "socket-patch", path: ...` Gemfile block; run `bundle plugin uninstall socket-patch`; remove `.socket/bundler-plugin/`, `.socket/gem-plugin-stamp`, and its `.socket/.gitignore` entry | + +Use `socket-patch list` to inspect the remaining patch set. For agent projects, +run `socket-patch apply` once after migration to confirm the manifest still applies. + +## Retired spellings + +| Removed | Replacement | +| --- | --- | +| `scan --redirect` | `scan --mode hosted` | +| `scan --detached` | `scan --mode vendored` is already manifest-free | +| `--mode host`, `--mode redirect`, `--mode vendor` | `hosted`, `hosted`, `vendored` respectively | +| `get --one-off`, `rollback --one-off`, `SOCKET_ONE_OFF` | No replacement; these had no implementation | +| `SOCKET_PATCH_PROXY_URL` | `SOCKET_PROXY_URL` | +| `SOCKET_PATCH_DEBUG` | `SOCKET_DEBUG` | +| `SOCKET_PATCH_TELEMETRY_DISABLED` | `SOCKET_TELEMETRY_DISABLED` | + +Legacy `.socket/packages/` archives are no longer read. Patch data uses diff +archives or blobs; cleanup commands remove obsolete package archives. diff --git a/docs/releasing.md b/docs/releasing.md index 383d6ed74..64463d92c 100644 --- a/docs/releasing.md +++ b/docs/releasing.md @@ -11,7 +11,7 @@ The CLI publishes to three channels, all from that single dispatch: The npm distribution is also required by the official Socket CLI. v5 no longer builds or publishes the PyPI and RubyGems CLI packages or their install hooks. -See the [migration instructions](../README.md#migrating-from-pypi-or-rubygems). +See the [migration instructions](migrating-to-v5.md#installation-channels). ## 1. Write the release notes diff --git a/docs/testing/README.md b/docs/testing/README.md new file mode 100644 index 000000000..c6970a50a --- /dev/null +++ b/docs/testing/README.md @@ -0,0 +1,50 @@ +# Testing + +Tests should establish that a package manager consumes the intended patched bytes, +that VEX describes the resulting state, and that reruns and reversal preserve +unrelated project data. See [development](../development.md#validation) for basic +Rust and Python checks. + +## Test layers + +| Layer | Location / entry point | Purpose | +| --- | --- | --- | +| Core unit tests and fixtures | `cargo test --locked -p socket-patch-core --lib`; core `tests/fixtures/` | Parsers, rewrites, integrity checks, and refusal cases | +| CLI parser and in-process tests | `crates/socket-patch-cli/tests/cli_parse_*.rs`, `in_process_*`, command suites | Flags, defaults, output, lifecycle, and failures | +| Native package-manager suites | CLI `e2e_redirect_*_build`, `e2e_vendor_*_build`, and VEX suites | Real installs against controlled patch inputs | +| Production suites | [Hosted](hosted-production-e2e.md), [vendored](vendored-production-e2e.md) | Real patch-service responses and artifact delivery | +| Release compatibility backtests | Package-manager guides below and `scripts/backtest-*.py` | Format and installer boundaries across published releases | +| Container suites | [Docker guide](../../tests/docker/README.md) | Toolchain isolation and offline installs | + +Native suites require the tools named in their guide. Opt-in or unavailable-toolchain +skips are not installation evidence. Use the suite's `*_REQUIRED` or `*_STRICT` +setting when that toolchain is required for the check. + +## Package-manager guides + +| Ecosystem | Guides | +| --- | --- | +| npm family | [npm](npm-compatibility.md), [pnpm](pnpm-compatibility.md), [Yarn Berry](yarn-berry-compatibility.md), [Bun](bun-compatibility.md), [vlt](vlt-compatibility.md) | +| Python | [uv](uv-compatibility.md), [Poetry](poetry-compatibility.md), [PDM](pdm-compatibility.md), [Pipenv](pipenv-compatibility.md), [Hatch](hatch.md) | +| PHP | [Composer](composer-compatibility.md) | + +Other ecosystems have Rust and container suites listed in +[ecosystem support](../ecosystems.md) and the Docker guide. + +## CI and results + +[CI](../../.github/workflows/ci.yml) separates normal PR coverage from broader +release, main-branch, nightly, and manual matrices. Package-manager compatibility +workflows define additional matrices. Read the workflow for the authoritative +versions, triggers, required flags, and artifact names. + +The vlt [compatibility tables](vlt-compatibility.md) define a generated leg manifest; +[`vlt-coverage.json`](vlt-coverage.json) maps diagnostics to tests. These are +executable specifications and are checked by `scripts/tests/`, not historical +reports. + +Backtest runners write JSON results and can render summary tables. Keep each run's +results, binary versions, source revision, and logs together in CI artifacts or a +local output directory. Update the maintained compatibility boundaries when new +evidence changes them. A past successful run or catalog snapshot is not a claim +that the current branch or production service passes today. diff --git a/docs/testing/bun-compatibility.md b/docs/testing/bun-compatibility.md index d6782a2ef..5b6320281 100644 --- a/docs/testing/bun-compatibility.md +++ b/docs/testing/bun-compatibility.md @@ -176,54 +176,14 @@ frozen and ordinary installs, and digest tampering. `cargo test -p socket-patch-cli --test e2e_bun_lockb` uses Bun on `PATH`; a modern Bun reads the committed binary fixture, so no separate old writer is needed. -### Measured validation - -Measured on 2026-09-21, macOS arm64, using the native binary implementation in -the worktree based on `4b61c9620b800d26056211060ebb4a4c60288da5`: - -| Suite | Result | Coverage | -|-------|--------|----------| -| Public patch service | 370 / 370 cases passed | 11 releases: 0.8.1, 1.0.0, 1.0.36, 1.1.0, 1.1.38, 1.1.45, 1.2.0, 1.2.23, 1.3.0, 1.3.14, 1.4.2. 340 accepted flows and 30 expected text-workspace refusals. Direct, alias, transitive, two-version, workspace, nested workspace, root workspace, lockfile-only, UUID/search get, legacy binary and both takeover shapes. | -| Explicit warm-cache installs | 90 / 90 cases passed | Six eras: 0.8.1, 1.0.36, 1.1.45, 1.2.23, 1.3.14, 1.4.2. Direct, workspace, nested workspace, legacy binary and both takeovers, with cold and warmed-cache frozen and ordinary installs. Includes eight expected text-workspace refusals. | -| Native binary writer/reader matrix | 25 / 25 pairs passed | All 17 fixture writers listed above; own-version readers from 0.5.9 onward, 0.5.9 readers for the three 0.1.x writers, five 1.2–1.4 readers of 1.1.45, and 1.4.2 readers of 0.1.1, 0.1.6 and 0.6.7. All three Rust acceptance tests ran in each pair. | -| Historical concurrency regression | 30 / 30 pairs passed | Six repetitions of 0.5.9 reading 0.1.1, 0.1.6 and 0.5.9, plus 1.4.2 reading 0.1.1 and 0.1.6, with isolated temporary directories. | - -The public-service captures record CLI SHA-256 -`a3e7683d66e6e6654644c3cd51ada1260a58a8d8f9b96c0a2ea4f585a9219910`. -The binary matrix records both Bun executable hashes and its test executable -hash in every result. The final local reports are under -`/tmp/socket-patch-bun-public-final`, `/tmp/socket-patch-bun-public-warm-final` -and `/tmp/socket-patch-bun-native-final-isolated`. - -Early parallel historical probes exposed Bun 0.5.9's `FileNotFound extracting -tarball` and Bun 0.1.1's lockfile `AccessDenied` errors in a shared temporary -directory. The harness now gives every fixture its own temporary directory and -an empty cache directory. Historical writers use timestamp-derived temporary -names. The failing logs remain under `/tmp/socket-patch-bun-native-verified` and -`/tmp/socket-patch-bun-native-emptycache-*`; the six repeated runs above verify -the corrected isolation without retrying failed assertions or changing readers. - -On 2026-09-22, the full workspace test run passed 7,326 tests with no failures, -and production Clippy passed with warnings denied. The production-filter -regression passed all 33 public-service cases across the same 11 release eras, -including cold and warmed-cache frozen and ordinary installs. A separate complex -graph passed both scoped rollback orders on 0.8.1 and 1.0.0; that graph is now -part of the permanent binary matrix. These local measurements use macOS arm64. - -The [PR validation run for `9644add`](https://github.com/SocketDev/socket-patch/actions/runs/35729497310) -also passed all 25 native binary writer/reader pairs on macOS and all 13 pairs -available on Windows, including the permanent production/scoped-rollback cases. -Windows has no official Bun binaries before 1.1.0. Each pair ran all three Rust -acceptance tests. - -The Linux runner exposed a separate historical-runtime boundary: official Bun -0.5.9, 0.6.7 and 0.6.8 crashed with `SIGSEGV` during pristine installs on -`ubuntu-latest` (Ubuntu 24.04), before `socket-patch` ran. The workflow retains -all 25 required historical pairs on Ubuntu 22.04, and additionally runs the 16 -pairs using Bun 0.8.1 and later on `ubuntu-latest`; every historical format and -reader remains in the required matrix. Linux failures upload bounded pristine -runtime probes and, when available, syscall traces under the binary result artifact's -`linux-diagnostics/` directory. +### Historical runtime limitations + +The binary matrix keeps each fixture's temporary directory and cache isolated; +old Bun writers can collide when sharing temporary paths. Windows has no official +Bun binaries before 1.1.0. Official Bun 0.5.9, 0.6.7, and 0.6.8 can crash during +pristine installs on Ubuntu 24.04, before Socket Patch runs; the compatibility +workflow retains those historical pairs on Ubuntu 22.04. Read the workflow and +its uploaded diagnostics for each run's coverage and results. ## Installer boundaries (measured) diff --git a/docs/testing/hosted-production-e2e.md b/docs/testing/hosted-production-e2e.md index c874d8915..1af30895b 100644 --- a/docs/testing/hosted-production-e2e.md +++ b/docs/testing/hosted-production-e2e.md @@ -1,290 +1,103 @@ -# Hosted-mode production e2e +# Hosted production tests -`crates/socket-patch-cli/tests/e2e_hosted_production.rs` is the only test suite -in this repo that exercises [hosted mode](../ecosystems.md#mode--ecosystem-matrix) -(`scan --mode hosted`) against the **real** Socket production service with **no -mocking anywhere**. Every other hosted-mode capstone (`e2e_redirect_*_build.rs`) -serves the patch artifact from a local wiremock, which proves the CLI's rewrite -grammar but cannot notice production drifting away from it. +[`e2e_hosted_production.rs`](../../crates/socket-patch-cli/tests/e2e_hosted_production.rs) +exercises hosted patching against Socket's production public proxy, patch server, +and upstream registries. It complements controlled-input native installer suites, +which can validate rewrite behavior without detecting production-service drift. ## What it proves -For each ecosystem × package manager: - -1. install a pinned, known-vulnerable dependency from its **real** upstream - registry with the **real** package manager; -2. assert the installed bytes are pristine (anti-vacuity); -3. `socket-patch scan --mode hosted --json --yes` — resolves a hosted patch - reference from `patches-api.socket.dev` and rewrites the lockfile / registry - config to point at `patch.socket.dev`; -4. assert the rewrite landed (patch host + patch UUID present, integrity pin - replaced); -5. **wipe the install tree and reinstall from the rewritten lock alone** — the - package manager itself fetches from `patch.socket.dev` and verifies the - integrity pin it was handed; -6. assert the reinstalled bytes carry the patch. - -Step 5 is the point. It is the only place in this repo where a third-party -package manager — not socket-patch — downloads a Socket-hosted artifact and -independently verifies its checksum. - -## Required production patches - -The suite is pinned to these patches. They must stay **published** and -**free-tier** on `patches-api.socket.dev`; the suite runs against the -unauthenticated public proxy on purpose, because that is the surface every user -without a token gets. No API token is used, and `SOCKET_API_TOKEN` is scrubbed -from the child environment. - -| Ecosystem | PURL | Patch UUID | Advisory | Used by | -|-----------|------|------------|----------|---------| -| npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | GHSA-xvch-5gv4-984h / CVE-2021-44906 | every npm-family leg (npm, npm-shrinkwrap, pnpm, yarn classic, yarn berry, bun, vlt) | -| PyPI | `pkg:pypi/urllib3@1.26.18` | `de58c8b8-796c-4b6d-8a48-539b5563db76`, `26242e35-f867-4da8-8789-f0d2ea49e0f1`, `e828efa5-5c6d-43f3-9909-03f5ac232b98` | GHSA-38jv-5279-wg99, GHSA-2xpw-w6gg-jr37, GHSA-gm62-xv2j-4w53 | requirements.txt, uv.lock | -| RubyGems | `pkg:gem/activestorage@6.0.3` | any of `15e960b5-f432-4b6c-b8aa-534a2b419323` (GHSA-m42x-37p3-fv5w / CVE-2020-8162), `6c4141c5-1535-4fd2-9db1-b5f8e4834bdb` (GHSA-w749-p3v6-hccq / CVE-2022-21831, published 2026-08-19), `eeb6bf9f-96c0-4963-a0f1-2e88f91f8b1a` (GHSA-9xrj-h377-fr87 / CVE-2026-33195, published 2026-08-20), `c1a1cd3c-b670-4e44-b4fa-1a63ecd42db6` (GHSA-r4mg-4433-c7g3 / CVE-2025-24293, published 2026-08-20), `9c2b4925-b413-4a3a-bb3a-9990440fb446` (GHSA-xr9x-r78c-5hrm / CVE-2026-66066, published 2026-08-21), `01019627-b481-4bae-bc09-e93b5a5e4481` (MERGED: CVE-2022-21831 + CVE-2025-24293 + CVE-2026-66066, published 2026-09-04) | see UUID column | bundler leg | - -urllib3 1.26.18 carries **three** distinct free patches, one per advisory. The -CLI picks one with its own ranking -(`crates/socket-patch-core/src/api/ranking.rs`) over server-supplied severity -and publish dates, so a newly published or re-scored patch can change the pick; -the suite therefore accepts any of the three rather than pinning one. - -`preflight_required_patches_are_published` checks all three every run and fails -first with the offending PURL named, so a withdrawn patch produces one clear -failure instead of N confusing ones that look like CLI regressions. +Each install-proof case installs a pinned upstream package, checks that its bytes +are pristine, runs a hosted scan, and verifies the new reference and integrity pin. +It then removes the installed tree, installs from the changed dependency files with +fresh caches, and verifies patched bytes. The suite also exercises manifest-free +VEX. This proves delivery of the selected patch; it does not test exploit efficacy. + +## Catalog fixtures and coverage + +The test's catalog constants and preflight checks are authoritative for required +PURLs, patch UUIDs, and byte markers. They use free patches through +`patches-api.socket.dev`, with ambient authentication scrubbed. Catalog contents +can change independently of this repository; do not treat a past run as a current +publication guarantee. + +| Coverage | Cases | +| --- | --- | +| Native production installs | npm/shrinkwrap, pnpm, Yarn Classic, Yarn Berry with node-modules, Bun, pip requirements, uv, and Bundler | +| Conditional production proof | vlt: validates the served encoding before attempting installation | +| Catalog canaries | Cargo, Maven, NuGet, and Composer: detect when a free fixture becomes available; do not prove an install | +| Go | Validates the required hosted reference shape; see [Go support](../ecosystems.md#go-directory-replaces-and-gosum) | +| Unsupported mode | Deno hosted refusal | + +Poetry, PDM, and Pipenv production installers are covered by their +[release backtests](README.md#package-manager-guides). Rush and Yarn PnP are not +production install-proof cases in this suite. Controlled fixtures and production +coverage are distinct; neither should be inferred from the other. ### If a required patch is withdrawn -1. Find a replacement in the same ecosystem: - ```sh - # version-less lookup lists every patched version of a package - curl -s 'https://patches-api.socket.dev/patch/by-package/pkg%3Anpm%2Flodash' | jq - ``` - Prefer a package that is small, dependency-free, and installable by every - package manager in that ecosystem's leg. -2. Update the catalog constants at the top of `e2e_hosted_production.rs` - (`*_PURL`, `*_NAME`, `*_VERSION`, `*_UUID`) **and** the table above. -3. If the new patch does not inject the `// Socket Community Patch` header, - pick a marker unique to the patch and set the ecosystem's `*_MARKER` - constant. - -## Ecosystem coverage, and the honest gaps - -| Ecosystem | Hosted mode | Free patches in production | Suite coverage | -|-----------|-------------|----------------------------|----------------| -| npm | ✅ | ✅ many | ✅ npm, npm-shrinkwrap, pnpm, yarn classic, yarn berry, bun; vlt probe-driven (see [vlt](#vlt-the-serve-encoding-gate)) | -| PyPI | ✅ (requirements.txt, uv.lock, poetry.lock, pdm.lock, Pipfile.lock) | ✅ many | ✅ requirements.txt, uv.lock (poetry.lock / pdm.lock / Pipfile.lock via per-release backtests, see below) | -| RubyGems | ✅ | ✅ (this suite pins one purl/UUID: `activestorage@6.0.3`; the 2026-08-18 republish covers more versions) | ✅ full bundler install proof | -| Cargo | ✅ | ❌ **none** (tier emptied 2026-08-28) | canary only | -| Maven | ✅ | ❌ **none** | canary only | -| NuGet | ✅ | ❌ **none** | canary only | -| Composer | ✅ | ❌ **none** | canary only | -| Go | ✅ free tier [by design](../design/golang-hosted.md) (paid: ❌ [analysis](../design/golang-hosted-no-go.md)) | ❌ none published yet | shape guard (redirects only via `goproxy` override) | -| Deno | ❌ not supported | — | negative assertion | - -Cargo, Maven, NuGet and Composer all *implement* hosted mode, but production -publishes **zero** free-tier patches for them, so there is nothing real to -redirect to. Rather than skipping silently, `canary_unpublished_ecosystems` -probes production every run and reports the moment that changes, so coverage -can be extended deliberately. It does not fail when patches appear — production -publishing a patch is not a socket-patch regression — but -`SOCKET_PATCH_HOSTED_E2E_CANARY_STRICT=1` makes it fail, for use in a scheduled -nag run. - -**Cargo was demoted to the canary on 2026-09-01.** Until then the suite carried -a full sparse-registry install proof pinned to one crate, but production's free -cargo tier emptied on 2026-08-28 (both pinned patches were deleted server-side, -leaving zero live free patches for any cargo crate), so there is nothing honest -left to pin. This deliberately drops the cargo install-proof coverage — the -canary only watches for the tier lighting up again. To re-promote cargo: pick a -live free patch and follow -[the withdrawn-patch procedure](#if-a-required-patch-is-withdrawn); the git -history of this demotion shows every piece to restore (catalog constants, -preflight registration, the install-proof leg, and these tables) in both -production suites. - -PyPI's `poetry.lock`, `pdm.lock` and `Pipfile.lock` ARE rewritten by hosted -mode (Poetry 1.0+; PDM lock formats `2` and `4.3`–`4.5.1`; Pipenv 7+); their -live coverage is the per-release matrices in -[poetry-compatibility.md](poetry-compatibility.md) (`scripts/backtest-poetry.py`), -[pdm-compatibility.md](pdm-compatibility.md) (`scripts/backtest-pdm.py`) and -[pipenv-compatibility.md](pipenv-compatibility.md) (`scripts/backtest-pipenv.py`), -which install the redirected lock with every release rather than one pinned -installer, so they are not duplicated as legs here. +1. Choose a published free patch in the same ecosystem, preferably a small package + supported by each affected installer. +2. Update the catalog constants, accepted patch set, and patched-byte marker in + both production suites. Read the selected record rather than assuming the + catalog's ranking is unchanged. +3. Run preflight and every affected native install proof. Keep the production + fixtures and assertions consistent; a missing fixture must not silently turn a + required install check into a pass. -Two supported hosted shapes are deliberately **not** covered here: - -* **npm Rush monorepos** — hosted mode supports them (`common/config/rush/pnpm-lock.yaml` - plus per-subspace locks), but a faithful leg needs a real `rush install`, which - is a much heavier fixture than everything else in this file. It also inherits - the pnpm issue below. Covered by `e2e_redirect_rush_sim.rs` against a mock. -* **yarn berry with the PnP linker** — documented as untested for hosted mode - (the lock rewrite fires, but PnP's `.yarn/cache` resolution is not exercised). - The berry leg here pins `nodeLinker: node-modules`, matching the documented - support boundary. +To promote a canary into installation coverage, add its catalog fixture, preflight +registration, install-proof test, and CI toolchain. Update this coverage table and +the [vendored suite](vendored-production-e2e.md) together. ## vlt: the serve-encoding gate -`vlt_pinned_matrix_production_hosted_install_proof` pins the public minimist -patch in a vlt 1.2.0 project (`vlt.json` with `registries.npm`). vlt hashes the -wire body of a tarball and sends `accept-encoding: gzip;q=1.0, identity;q=0.5`, -so it fails `EINTEGRITY` whenever patch.socket.dev (or its CDN) serves the -artifact content-encoded. The leg therefore probes the artifact the way vlt -does (the core `fetch_artifact_probe`) and branches on what it sees: - -| Probe | Asserted | -|---|---| -| `Content-Encoding` other than identity | the clean refusal: `redirect_vlt_artifact_unverifiable` naming the encoding, `vlt-lock.json` byte-identical (v5 hosted mode writes no ledger either way). With `SOCKET_PATCH_VLT_HOSTED_PRODUCTION_REQUIRED=1` the encoded response is itself a failure. | -| identity | the full proof: slot [2] is the served sha512, and a fresh checkout's `vlt ci` installs the patched minimist | - -So the leg neither breaks nor goes vacuous when the serve fix -(`Cache-Control: no-transform`) deploys. As of 2026-09-26 production still -re-gzips the artifact and the leg runs the refusal branch. Under -`SOCKET_PATCH_HOSTED_E2E_STRICT=1` a missing `SOCKET_PATCH_VLT_E2E_JS` fails -instead of skipping, and CI runs the leg's output through -`scripts/check-vlt-legs.py`. `.github/workflows/vlt-serve-watchdog.yml` probes -the same artifact every 6 hours; see [vlt compatibility](vlt-compatibility.md). - -## Known issues this suite surfaced - -All were found by running against real production; none is a test bug. - -### 1. `gem` — hosted mode was unusable for gems with dependencies (SERVER) — FIXED - -Socket's gem patch-registry used to serve a compact index whose `/info/` -line declared **no runtime dependencies** while the `.gem` it served declared -several, so bundler's `ensure_same_dependencies` check failed closed with -`Bundler::APIResponseMismatchError` — hosted gem mode was unusable for any gem -with runtime dependencies. (The suite's original pin, activestorage@7.0.2.2 / -`2535d43d-…` / GHSA-w749-p3v6-hccq, was unpublished on 2026-08-14 pending the -fix.) - -**Fixed by the 2026-08-18 gem catalog republish**: the patch-registry's compact -index now serves the gemspec's runtime dependencies (verified against -activestorage@6.0.3: `/versions` 200, `/info/activestorage` 200 with the full -dep list). The leg's probe-based tolerance — pass on a non-2xx `/versions`, -enforce on 2xx — retired itself as designed and was deleted along with its -`SOCKET_PATCH_HOSTED_E2E_GEM_STRICT` knob; the leg is now the unconditional -`gem_bundler_hosted_install_proof`. - -**Latent, still open (server)**: the registry's `/api/v1/dependencies` route -answers 200 with an empty body. Unreachable today — bundler only falls back to -the Dependency fetcher when the compact index is unavailable — but it would -resurface as a confusing Marshal error if the compact index ever broke again. - -### 2. `pnpm` — trust configuration and cache handling - -The CLI now configures `trustLockfile: true` for root lockfileVersion 9 projects -unless the project explicitly disables it or the user passes -`--no-trust-lockfile-config`. This accepts hosted tarball URLs on pnpm >=11; -it disables registry re-verification for the entire lock while retaining -per-artifact integrity checks. The historical missing-warning gap is closed. - -An installed tree or warm store can still retain upstream bytes. Use a clean -install tree and an empty store, then verify with `socket-patch vex`. -`--force` alone is not a portable recovery. The required -[pnpm compatibility matrix](pnpm-compatibility.md) tests this distinction, -integrity rejection, peer instances, and rollback across pnpm majors 1–12. -The production pnpm test proves installation from the public hosted service; -it does not test the SBOM backend, dashboard badges, policies, or alert counts. +vlt verifies the raw response body. If the patch server returns a content-encoded +artifact, the hosted CLI refuses it with `redirect_vlt_artifact_unverifiable` and +leaves the lock unchanged. The production leg probes the artifact using vlt's +request headers and asserts either that refusal or, for identity encoding, the +full fresh-checkout `vlt ci` proof. -### 3. `uv.lock` — the `sdist` entry was rewritten to a wheel URL (CLI) — FIXED - -The uv.lock rewriter used to point the `sdist` entry at the patched wheel while -keeping the original sdist's `size`. It now drops the entry's existing -`sdist` / `wheel` / `wheels` / `archive` keys and writes back only the -redirected artifact (a wheel goes in `wheels`), pinned by the urllib3 1.26.18 -unit test in `crates/socket-patch-core/src/utils/python_lock.rs`. +`SOCKET_PATCH_VLT_HOSTED_PRODUCTION_REQUIRED=1` requires the install branch and +fails on an encoded response. The +[serve watchdog](../../.github/workflows/vlt-serve-watchdog.yml) monitors this +boundary; the current run's probe, not a dated note, determines server behavior. +The [vlt guide](vlt-compatibility.md) defines the required leg reporting. ## Running ```sh -# everything, soft-skipping legs whose toolchain is absent -cargo test -p socket-patch-cli --test e2e_hosted_production -- --ignored +cargo test --locked -p socket-patch-cli --test e2e_hosted_production -- --ignored -# one leg -cargo test -p socket-patch-cli --test e2e_hosted_production -- --ignored \ - yarn_berry_hosted_install_proof --nocapture +# One install proof: +cargo test --locked -p socket-patch-cli --test e2e_hosted_production -- \ + --ignored yarn_berry_hosted_install_proof --nocapture ``` -The suite is `#[ignore]`-gated, so it stays out of the `test` and `e2e` jobs and -runs only where it is explicitly asked for. - -### Environment knobs +The suite is opt-in. Missing tools can skip local cases; use strict mode when +coverage is required. | Variable | Effect | -|----------|--------| -| `SOCKET_PATCH_HOSTED_E2E_STRICT=1` | Turn every "toolchain missing" soft-skip into a hard failure. **CI sets this** — a required check must never report green on an unexercised leg. | -| `SOCKET_PATCH_HOSTED_E2E_CANARY_STRICT=1` | Fail when cargo/maven/nuget/composer gain their first free published patch. | -| `SOCKET_PATCH_VLT_E2E_JS` / `SOCKET_PATCH_VLT_E2E_VERSION` | The vlt release the vlt leg runs (`node `, exact `--version`); CI installs 1.2.0 with `scripts/install-vlt.sh`. | -| `SOCKET_PATCH_VLT_HOSTED_PRODUCTION_REQUIRED=1` | Fail the vlt leg while the artifact is served content-encoded. Unset until the serve fix is verified in production. | - -### Toolchains - -`npm`, `corepack` (pnpm + yarn classic + yarn berry), `bun`, `vlt` (Node ≥ 22.22), `uv`, -`ruby` + `bundle` (**≥ 2.6** — `bundle lock --add-checksums` emits the CHECKSUMS -section the gem rewrite pins into), `go`. - -### Network egress - -`patches-api.socket.dev`, `patch.socket.dev`, `registry.npmjs.org`, `pypi.org`, -`files.pythonhosted.org`, `rubygems.org`. - -## CI: the `hosted-e2e` job - -Defined in `.github/workflows/ci.yml`. It is intended to be a **required** status -check in branch protection, registered under exactly the name `hosted-e2e`. - -The job deliberately has **no** job-level `if:`, **no** `needs:`, **no** matrix -and **no** `continue-on-error`. A *skipped* required check is ambiguous to branch -protection and can wedge a PR at "Expected — waiting for status", so the job -always runs and always reaches success or failure; the kill switch gates the -*steps*, not the job. - -It retries the suite up to three times with backoff, because the public proxy -intermittently returns 503 "Service temporarily over capacity" — the documented -reason the older live-API suites were pulled from the PR matrix. - -The job installs `bun@1` through npm, so its bun leg (`bun_hosted_install_proof`) -runs against whatever 1.x release that resolves to (a lockfileVersion-2 lock -today). Lock-era coverage — version-0 and version-1 locks, native `bun.lockb` -rewrites, the 1.3.10 digest boundary — lives in `ci.yml`'s hermetic -`e2e_redirect_bun_build` legs and in `bun-compatibility.yml`; see -[Bun compatibility](bun-compatibility.md). - -The job also installs vlt 1.2.0 (`scripts/install-vlt.sh`: `npm pack`, the -tarball's sha512 checked against the registry and -`scripts/vlt-historical-integrity.json`), exports `SOCKET_PATCH_VLT_E2E_JS`, -`_VERSION` and `_REQUIRED=1`, checks the passing attempt's vlt leg with -`scripts/check-vlt-legs.py`, and then runs the vendored vlt proof -(`e2e_vendored_production -- --include-ignored vlt_pinned_matrix`) with the -same retries. Release-era coverage lives in `ci.yml`'s `e2e` vlt rows and in -`vlt-compatibility.yml`; see [vlt compatibility](vlt-compatibility.md). - -### Escape hatch — production is down and this is blocking merges - -Set a repository variable (Settings → Secrets and variables → Actions → -Variables): - -``` -HOSTED_E2E_DISABLED = true -``` - -then hit **Re-run failed jobs** on any blocked PR. `vars` is read at job-run -time, so no commit and no push is needed: the job goes green with a loud -`::warning::` and a **BYPASSED** banner in the job summary, and every open PR -clears on its next re-run. - -**Delete the variable to re-arm.** Any value other than exactly `true` (including -`yes`, `1`, `True`) leaves the suite armed — a typo must not silently disable -production coverage. - -For a single run without touching the variable: **Actions → CI → Run workflow**, -then `hosted_e2e = force` (ignore the variable) or `skip` (bypass this run). - -### Turning it on - -The job runs as soon as this lands. Making it *required* is a one-time repo -setting, done after the first green run on `main`: - -> Settings → Branches → branch protection rule for `main` → Require status -> checks to pass → add **`hosted-e2e`**. +| --- | --- | +| `SOCKET_PATCH_HOSTED_E2E_STRICT=1` | Fail instead of skipping missing required toolchains | +| `SOCKET_PATCH_HOSTED_E2E_CANARY_STRICT=1` | Fail when a watched ecosystem gains a free fixture, prompting promotion | +| `SOCKET_PATCH_VLT_E2E_JS` / `SOCKET_PATCH_VLT_E2E_VERSION` | Select an installed, version-pinned vlt executable | +| `SOCKET_PATCH_VLT_HOSTED_PRODUCTION_REQUIRED=1` | Require vlt's actual install proof rather than its encoding refusal | + +Tools include npm, Corepack for pnpm/Yarn, Bun, uv, Go, and Ruby/Bundler. The gem +proof requires Bundler 2.6+ for lockfile checksums. vlt requires its configured +Node runtime and executable. The workflow pins and provisions CI versions. +Network access includes Socket's public API and patch server, npm, PyPI, and +RubyGems registries. + +## CI and service outages + +The [`hosted-e2e` job](../../.github/workflows/ci.yml) runs independently of the +other test jobs and retries production failures up to three times. It also runs +the vendored vlt production proof and validates vlt leg output. Branch protection +settings are configured separately from the workflow. + +During a production outage, maintainers can set the repository Actions variable +`HOSTED_E2E_DISABLED` to exactly `true`, then rerun affected jobs. The steps report +**BYPASSED** in the job summary; that successful job is not test evidence. Delete +the variable to restore coverage. Manual workflow dispatch accepts `hosted_e2e` +values `force` (ignore the variable) or `skip` (bypass that run). diff --git a/docs/testing/npm-compatibility.md b/docs/testing/npm-compatibility.md index d7be6fc33..e8c1a05fa 100644 --- a/docs/testing/npm-compatibility.md +++ b/docs/testing/npm-compatibility.md @@ -26,9 +26,11 @@ npm 12 notes: dependencies. `allow-remote=all` is the setting a hosted redirect needs; it also admits any other url-resolved dependency (the per-entry sha512 pins stay enforced). The hosted run writes it to the project `.npmrc` (created, - or one appended line; ledger kind `redirect_npmrc_allow_remote`, removed by - `rollback` / `remove` / the vendored takeover once no package-lock entry - needs it), respects an explicit other value — in the project `.npmrc`, the + or one appended line). Hosted mode keeps no ledger. Once rollback, removal, + or vendored takeover removes the last hosted npm pin, an `.npmrc` containing + only that setting is deleted; a file with other settings is retained with + `npm_allow_remote_left`. The writer respects an explicit other value — in the + project `.npmrc`, the user / global / builtin npm config, or an `npm_config_allow_remote` environment variable (which beats every `.npmrc`) — and is disabled by `--no-npm-allow-remote-config`. @@ -59,7 +61,7 @@ npm 12 notes: | `e2e_redirect_npm_build` (`#[ignore]`) | real | scan / get-uuid / get-ghsa hosted redirects, shrinkwrap flavor, tampered-tarball rejection, fresh-checkout `npm ci`, manifest-less VEX tail | | `e2e_vendor_npm_build` | real | vendor / get-vendored, shrinkwrap flavor, npm 6 × v2 lock, idempotency, byte-exact revert, manifest-less VEX tail | | `e2e_vex_lockfile::npm` | none | tamper / spoof / mismatch / pin cells over lockfileVersion 1, 2, 3, shrinkwrap and dual-lock shapes | -| `redirect_npm_allow_remote` | none | the npm 12 `allow-remote` auto-config: `.npmrc` create / append (BOM, CRLF), explicit values respected (project file, user / global config, env var), unhonored spellings, bare-CR and indented-section files, section-scoped copies, opt-out flag + env, dry run, symlinked `.npmrc`, `--silent`, rollback removing exactly what was added, `remove` surfacing `redirect_npmrc_allow_remote_modified` | +| `redirect_npm_allow_remote` | none | the npm 12 `allow-remote` auto-config: `.npmrc` create / append (BOM, CRLF), explicit values respected (project file, user / global config, env var), unhonored spellings, bare-CR and indented-section files, section-scoped copies, opt-out flag + env, dry run, symlinked `.npmrc`, `--silent`, rollback/removal deleting a standalone setting or warning `npm_allow_remote_left` when other settings remain | | `e2e_hosted_production` / `e2e_vendored_production` (`#[ignore]`) | real (ambient) | the same flows against production, ending in the manifest-less VEX tail | The manifest-less VEX tail (`tests/npm_e2e_common/manifestless.rs`) runs four @@ -88,26 +90,5 @@ unreachable registry into a failure instead of a skip. 6 cross-version cell needs an npm >= 7 to write its v2 lock: `npm` on `PATH`, or `SOCKET_PATCH_NPM_E2E_LOCK_WRITER_BIN`. -## Local results (2026-09-22) - -Every row below ran both real-npm suites with `SOCKET_PATCH_NPM_E2E_REQUIRED=1` -on Node 24.21 (macOS): all 20 legs green, 77 manifest-less VEX matrices, each -with all four cells (manifest deleted, ledgers deleted, `--offline`, lock -reverted) passing. Re-run 2026-09-23 after the `.npmrc` auto-config landed: -`e2e_redirect_npm_build` on 10.9.9, 11.20.0 and 12.1.0 (every hosted flow -installs from the committed, auto-configured `.npmrc` with a plain `npm ci`; -the main capstone's `rollback` removes it) and `e2e_vendor_npm_build` on -12.1.0 (no `.npmrc`), all green with every manifest-less VEX cell passing. - -| npm | hosted flows (scan, get uuid, get GHSA, shrinkwrap) | hosted fresh install | vendored flows | vendored fresh install | -| --- | --- | --- | --- | --- | -| 6.14.18 | 4 | refused EINTEGRITY (fail closed); VEX cells on the lockfile basis | v1 lock refused; npm 6 × v2-lock cell | patched (from the v2 legacy mirror) | -| 7.0.0 | 4 | patched | vendor, get vendored, in-place VEX, shrinkwrap | patched | -| 7.24.2 | 4 | patched | 4 | patched | -| 8.19.4 | 4 | patched | 4 | patched | -| 9.0.0 | 4 | patched | 4 | patched | -| 9.9.4 | 4 | patched | 4 | patched | -| 10.9.9 | 4 | patched | 4 | patched | -| 11.20.0 | 4 | patched | 4 | patched | -| 12.0.0 | 4 | EALLOWREMOTE, then patched with `allow-remote=all` (measured before the auto-config) | 4 (shrinkwrap: both locks wired) | patched | -| 12.1.0 | 4 | patched with a plain `npm ci` from the auto-configured `.npmrc` (EALLOWREMOTE without it); `rollback` removes the `.npmrc` | 4 (shrinkwrap: both locks wired) | patched | +Full run results belong with the source revision and toolchain versions in CI +artifacts or a local output directory. See the [testing guide](README.md#ci-and-results). diff --git a/docs/testing/pdm-compatibility.md b/docs/testing/pdm-compatibility.md index 8090e4bbb..4541634b3 100644 --- a/docs/testing/pdm-compatibility.md +++ b/docs/testing/pdm-compatibility.md @@ -36,9 +36,10 @@ span-based edits, and produces byte-exact fragments for replay. The Both modes retain the package version, extras, groups, markers and the `content_hash`; no `pyproject.toml` edit is required. A repeated scan leaves the -lock unchanged (idempotent). Rollback restores the recorded original -fragments — one per patch, plus the legacy integrity-table entry — so a -`pdm.lock` the tool rewrote returns byte-for-byte to its pre-scan state. +lock unchanged (idempotent). Vendored rollback restores recorded fragments. +Hosted rollback reconstructs +upstream entries from registry metadata and may refuse after incompatible relocks; +it does not keep the original lockfile bytes. Refused before any write: a `[[package]]` locked at several versions (a marker fork), a user-authored `url`/`path`/VCS/`editable` source, an unsupported `lock_version` or `strategy`, hash-less `files`, malformed hashes, and a wheel @@ -61,11 +62,10 @@ Measured details: `pdm lock --refresh` and `pdm update ` re-resolve the entry back to the registry source. `content_hash` is unchanged by that, so `pdm lock --check` cannot detect the loss: re-run `socket-patch scan --mode …` after any of them, - or gate CI on `socket-patch vex`. A re-scan after a relock re-applies the - patch and **rebases** the ledger's recorded edits onto the relocked text - (pristine → current, never an appended chain), so `rollback` still lands on the - pristine lock afterwards. This matters most for CRLF locks, which PDM - re-renders to a different byte layout on relock. + or gate CI on `socket-patch vex`. Re-scan after a relock to restore patch references. + Vendored state records + reversible edits; hosted state is the lock itself, and reversal resolves + upstream metadata. - **Hosted mode verifies the lock's file hash** on install for every supported release (tamper the hash and `pdm sync` fails closed). Vendored mode's protection is the committed wheel bytes, verified by the same hash. @@ -111,42 +111,5 @@ every Windows cell used to skip, and a run whose cells all skip or whose PDM bootstrap fails is now an error. The matrix needs no Socket API token (the `urllib3@1.26.18` patch is a free tier). -> **Note (v5.0):** the "refused vendored scan still writes a `.socket/manifest.json` -> record" observation in the notes column below describes the 4.0.0 binary the run -> was captured with. Vendored mode is manifest-free since v5.0 — `scan --mode vendored` -> never writes `.socket/manifest.json` — so the note disappears on the next regeneration. - - - -Run captured 2026-09-18 on macOS-26.6.2-arm64-arm-64bit-Mach-O with socket-patch `socket-patch 4.0.0` (source `fixed2`, binary sha256 `b7ac2064ae2a466ab2d2bd74447ba1ae1f47b94943eab9a4310012fc253cac38`), 25 PDM releases, shapes: direct, transitive, dev, optional, extras, marker, marker-excluded, platform-linux, platform-windows, crlf, static-urls, space-unicode, dependency-groups, multi-target, two-versions, custom-lockfile, pep582. - -| PDM | Python | lock_version | hosted | vendored | agent | tamper rejected (H/V) | `pdm install` keeps lock (H/V) | relock keeps patch (H/V) | notes | -| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | -| 0.8.7 | 3.8 | — | refused (11 shapes) | 10/11 (11 shapes) | 7/8 (8 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version absent unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 0.12.3 | 3.8 | 2 | pass (12 shapes) | 11/12 (12 shapes) | 8/9 (9 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; relock dropped urllib3 1.26.18 (`transitive`: pinned resolution, no overrides on this release); re-scan then has nothing to redirect and rollback of the stale ledger exits 0/1; `pdm install` re-locked (extras,marker,marker-excluded,platform-linux,platform-windows): PDM's own freshness check flags its freshly generated lock as stale; patched install afterwards=false/true; use `pdm sync` | -| 1.0.0 | 3.8 | 2 | pass (12 shapes) | 11/12 (12 shapes) | 8/9 (9 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; relock dropped urllib3 1.26.18 (`transitive`: pinned resolution, no overrides on this release); re-scan then has nothing to redirect and rollback of the stale ledger exits 0/1 | -| 1.4.5 | 3.8 | 2 | pass (12 shapes) | 11/12 (12 shapes) | 8/9 (9 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; relock dropped urllib3 1.26.18 (`transitive`: pinned resolution, no overrides on this release); re-scan then has nothing to redirect and rollback of the stale ledger exits 0/1 | -| 1.8.5 | 3.8 | 3.1 | refused (11 shapes) | 10/11 (11 shapes) | 7/8 (8 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 3.1 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 1.12.8 | 3.8 | 3.1 | refused (12 shapes) | 11/12 (12 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 3.1 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 1.15.5 | 3.8 | 3.1 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 3.1 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.0.3 | 3.11 | 4.0 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 4.0 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.1.5 | 3.11 | 4.0 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 4.0 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.2.1 | 3.11 | 4.0 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 4.0 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.3.4 | 3.11 | 4.1 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 4.1 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.6.1 | 3.11 | 4.2 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 4.2 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.7.4 | 3.11 | 4.2 | refused (12 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | n/a / n/a | n/a / n/a | n/a / n/a | lock_version 4.2 unsupported: refused before any write, native install intact; `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record; lock-only checkout (nothing installed) is not redirected | -| 2.8.2 | 3.11 | 4.3 | pass (13 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.9.3 | 3.11 | 4.3 | pass (13 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); agent mode on a `__pypackages__` project patched the PATH interpreter's site-packages; refused vendored scan still writes a `.socket/manifest.json` record | -| 2.10.4 | 3.11 | 4.4 | pass (13 shapes) | 12/13 (13 shapes) | 8/9 (9 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.11.2 | 3.11 | 4.4.1 | pass (14 shapes) | 13/14 (14 shapes) | 9/10 (10 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.12.4 | 3.11 | 4.4.1 | pass (14 shapes) | 13/14 (14 shapes) | 9/10 (10 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.15.4 | 3.11 | 4.4.1 | pass (14 shapes) | 13/14 (14 shapes) | 9/10 (10 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.17.3 | 3.11 | 4.5.0 | pass (16 shapes) | 15/16 (16 shapes) | 10/11 (11 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.20.1 | 3.11 | 4.5.0 | pass (17 shapes) | 16/17 (17 shapes) | 11/12 (12 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.22.4 | 3.12 | — | n/a | n/a | n/a | n/a / n/a | n/a / n/a | n/a / n/a | lock_version absent | -| 2.25.9 | 3.12 | — | n/a | n/a | n/a | n/a / n/a | n/a / n/a | n/a / n/a | lock_version absent | -| 2.27.0 | 3.13 | 4.5.0 | pass (17 shapes) | 16/17 (17 shapes) | 11/12 (12 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | -| 2.29.2 | 3.13 | 4.5.1 | pass (17 shapes) | 16/17 (17 shapes) | 11/12 (12 shapes) | yes / yes | yes / yes | false / false | `__pypackages__` layout: crawler does not see it (falls through to the PATH interpreter); refused vendored scan still writes a `.socket/manifest.json` record | - - +Full run results belong with the source revision and toolchain versions in CI +artifacts or a local output directory. See the [testing guide](README.md#ci-and-results). diff --git a/docs/testing/pdm-compatibility/results.json b/docs/testing/pdm-compatibility/results.json deleted file mode 100644 index e6a84ee23..000000000 --- a/docs/testing/pdm-compatibility/results.json +++ /dev/null @@ -1,29124 +0,0 @@ -{ - "provenance": { - "capturedAt": "2026-09-18T00:43:22.692909+00:00", - "cliPath": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/9840a7e8-5cf9-4f42-8960-54a9c23b7cd7/scratchpad/socket-patch-fixed2", - "cliRevision": "fixed2", - "cliSha256": "b7ac2064ae2a466ab2d2bd74447ba1ae1f47b94943eab9a4310012fc253cac38", - "cliVersion": "socket-patch 4.0.0", - "hostPython": "3.14.3", - "modes": [ - "hosted", - "vendored", - "agent" - ], - "patchUuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "pdmVersions": [ - "0.8.7", - "0.12.3", - "1.0.0", - "1.4.5", - "1.8.5", - "1.12.8", - "1.15.5", - "2.0.3", - "2.1.5", - "2.2.1", - "2.3.4", - "2.6.1", - "2.7.4", - "2.8.2", - "2.9.3", - "2.10.4", - "2.11.2", - "2.12.4", - "2.15.4", - "2.17.3", - "2.20.1", - "2.22.4", - "2.25.9", - "2.27.0", - "2.29.2" - ], - "platform": "macOS-26.6.2-arm64-arm-64bit-Mach-O", - "shapes": [ - "direct", - "transitive", - "dev", - "optional", - "extras", - "marker", - "marker-excluded", - "platform-linux", - "platform-windows", - "crlf", - "static-urls", - "space-unicode", - "dependency-groups", - "multi-target", - "two-versions", - "custom-lockfile", - "pep582" - ], - "toolsDir": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/9840a7e8-5cf9-4f42-8960-54a9c23b7cd7/scratchpad/pdm-venvs", - "uvVersion": "uv 0.11.19 (7b2cff1c3 2026-06-03 aarch64-apple-darwin)" - }, - "shapes": null, - "results": [ - { - "pdm": "0.8.7", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 38 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ] - }, - "applied": 1, - "codes": [ - "package_not_installed" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "0.8.7", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_version_unsupported", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "space-unicode", - "mode": "agent", - "outcome": "SKIP", - "python": "3.8", - "baselineFresh": true, - "info": {} - }, - { - "pdm": "0.8.7", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.8.7", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "0.8.7", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "python": "3.8", - "expected": "refused: lock_version None is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 39 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "2", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ] - }, - "applied": 1, - "codes": [ - "package_not_installed" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "0.12.3", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "2", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_package_missing", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": false, - "info": { - "ordinaryInstall": { - "baselineFresh": false, - "exit": 0, - "lockStable": false - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "0.12.3", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "0.12.3", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "note": "relock dropped urllib3 1.26.18 from the lock; re-scan/rollback recorded only", - "pyprojectUnchanged": true, - "targetKept": false - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "rollbackAfterRelock": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - } - } - }, - { - "pdm": "0.12.3", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rescanAfterRelock": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_package_missing", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "patchInLock": false - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "note": "relock dropped urllib3 1.26.18 from the lock; re-scan/rollback recorded only", - "pyprojectUnchanged": true, - "targetKept": false - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "rollbackAfterRelock": { - "exit": 1, - "failed": [], - "lockEqualsRelocked": true, - "status": "partial_failure" - } - } - }, - { - "pdm": "1.0.0", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 1, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 1, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 1, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 39 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "2", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ] - }, - "applied": 1, - "codes": [ - "package_not_installed" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "1.0.0", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 1, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "2", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_package_missing", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 38 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.0.0", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.0.0", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "note": "relock dropped urllib3 1.26.18 from the lock; re-scan/rollback recorded only", - "pyprojectUnchanged": true, - "targetKept": false - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "rollbackAfterRelock": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - } - } - }, - { - "pdm": "1.0.0", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rescanAfterRelock": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_package_missing", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "patchInLock": false - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "note": "relock dropped urllib3 1.26.18 from the lock; re-scan/rollback recorded only", - "pyprojectUnchanged": true, - "targetKept": false - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "rollbackAfterRelock": { - "exit": 1, - "failed": [], - "lockEqualsRelocked": true, - "status": "partial_failure" - } - } - }, - { - "pdm": "1.4.5", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 48 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "2", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 2, - "crawled": [ - "pkg:pypi/jaraco-context@6.0.1", - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ] - }, - "applied": 2, - "codes": [ - "package_not_installed" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "1.4.5", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "2", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_package_missing", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "1.4.5", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.4.5", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "note": "relock dropped urllib3 1.26.18 from the lock; re-scan/rollback recorded only", - "pyprojectUnchanged": true, - "targetKept": false - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_refused", - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@1.26.20" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 51 - }, - "applied": 1, - "codes": [ - "redirect_pdm_legacy_sync_required", - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "rollbackAfterRelock": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - } - } - }, - { - "pdm": "1.4.5", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "2", - "python": "3.8", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rescanAfterRelock": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_package_missing", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "patchInLock": false - }, - "relock": { - "crlfKept": null, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "note": "relock dropped urllib3 1.26.18 from the lock; re-scan/rollback recorded only", - "pyprojectUnchanged": true, - "targetKept": false - }, - "applied": 1, - "codes": [ - "pypi_pdm_legacy_sync_required", - "vendor_prebuilt_downloaded" - ], - "rollbackAfterRelock": { - "exit": 1, - "failed": [], - "lockEqualsRelocked": true, - "status": "partial_failure" - } - } - }, - { - "pdm": "1.8.5", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.8", - "info": {} - }, - { - "pdm": "1.8.5", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.8", - "info": {} - }, - { - "pdm": "1.8.5", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "extras", - "mode": "agent", - "outcome": "SKIP", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": {} - }, - { - "pdm": "1.8.5", - "shape": "extras", - "mode": "hosted", - "outcome": "SKIP", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "extras", - "mode": "vendored", - "outcome": "SKIP", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ] - }, - "applied": 1, - "codes": [ - "package_not_installed" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "1.8.5", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_version_unsupported", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 35 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.8.5", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 4, - "redirected": 0, - "scannedPackages": 38 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.8.5", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.8", - "info": {} - }, - { - "pdm": "1.12.8", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.8", - "info": {} - }, - { - "pdm": "1.12.8", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 37 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ] - }, - "applied": 1, - "codes": [ - "package_not_installed" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "1.12.8", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_version_unsupported", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 36 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.12.8", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 4, - "redirected": 0, - "scannedPackages": 39 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.12.8", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 24 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 26 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 25 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "3.1", - "python": "3.8", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "1.15.5", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 29 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "1.15.5", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "3.1", - "python": "3.8", - "expected": "refused: lock_version '3.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 45 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.0.3", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 48 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.0.3", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.1.5", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 47 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.1.5", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.2.1", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 47 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.2.1", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.0", - "python": "3.11", - "expected": "refused: lock_version '4.0' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.3.4", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 46 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.3.4", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.1", - "python": "3.11", - "expected": "refused: lock_version '4.1' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.6.1", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 46 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.6.1", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "crlf", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "crlf", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "dev", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "dev", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "direct", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "direct", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "extras", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "extras", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "marker", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "marker", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "optional", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "optional", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "pep582", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.2", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.7.4", - "shape": "transitive", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 0, - "scannedPackages": 46 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.7.4", - "shape": "transitive", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.2", - "python": "3.11", - "expected": "refused: lock_version '4.2' is not supported by the rewriter", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_lock_version_unsupported" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.8.2", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 46 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.8.2", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 45 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 46 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18" - ] - }, - "applied": 1, - "codes": [], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "2.9.3", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.3", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "patchedOutsideProject": { - "applied": 1, - "crawled": [ - "pkg:pypi/urllib3@1.26.18" - ] - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "rollbackOutsideProject": { - "exit": 0, - "restored": true - } - } - }, - { - "pdm": "2.9.3", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.9.3", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 4, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.9.3", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.3", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 42 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.10.4", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_stale_install_risk" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 47 - }, - "applied": 1, - "codes": [ - "redirect_pdm_stale_install_risk", - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.10.4", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.11.2", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 48 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.11.2", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 44 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.12.4", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 48 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.12.4", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.4.1", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.15.4", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 46 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.15.4", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.4.1", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "multi-target", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "multi-target", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "multi-target", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.17.3", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 46 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "two-versions", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.17.3", - "shape": "two-versions", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "pkg:pypi/urllib3@2.2.3?artifact_id=py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_forked_package", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": true, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 41 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "dependency-groups", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "dependency-groups", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "dependency-groups", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 43 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "multi-target", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "multi-target", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "multi-target", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 42 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.20.1", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 46 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.11", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "two-versions", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 43 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.20.1", - "shape": "two-versions", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.11", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "pkg:pypi/urllib3@2.2.3?artifact_id=py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_forked_package", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.22.4", - "shape": "crlf", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "crlf", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "crlf", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "dependency-groups", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "dependency-groups", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "dependency-groups", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "dev", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "dev", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "dev", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "direct", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "direct", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "direct", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "extras", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "extras", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "extras", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "marker", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "marker", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "marker", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "multi-target", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "multi-target", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "multi-target", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "optional", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "optional", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "optional", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "pep582", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "pep582", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "pep582", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "space-unicode", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "static-urls", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "static-urls", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "static-urls", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "transitive", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "transitive", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "transitive", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "two-versions", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.22.4", - "shape": "two-versions", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "crlf", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "crlf", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "crlf", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "dependency-groups", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "dependency-groups", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "dependency-groups", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "dev", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "dev", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "dev", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "direct", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "direct", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "direct", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "extras", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "extras", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "extras", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "marker", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "marker", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "marker", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "multi-target", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "multi-target", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "multi-target", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "optional", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "optional", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "optional", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "pep582", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "pep582", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "pep582", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "space-unicode", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "static-urls", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "static-urls", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "static-urls", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "transitive", - "mode": "agent", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "transitive", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "transitive", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "two-versions", - "mode": "hosted", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.25.9", - "shape": "two-versions", - "mode": "vendored", - "outcome": "SKIP", - "python": "3.12", - "info": {} - }, - { - "pdm": "2.27.0", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.13", - "expected": "no-op: the CLI only reads pdm.lock", - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 44 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.13", - "expected": "no-op: the CLI only reads pdm.lock", - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "dependency-groups", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "dependency-groups", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "dependency-groups", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 46 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "multi-target", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "multi-target", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "multi-target", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.0", - "python": "3.13", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.0", - "python": "3.13", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 45 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.27.0", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.0", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "two-versions", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.13", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 46 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.27.0", - "shape": "two-versions", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.0", - "python": "3.13", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "pkg:pypi/urllib3@2.2.3?artifact_id=py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_forked_package", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "crlf", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "crlf", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "crlf", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": false, - "equalsOriginal": false, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "custom-lockfile", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.1", - "python": "3.13", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [], - "exit": 0, - "lockfileOnlyPackages": 0, - "redirected": 0, - "scannedPackages": 48 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "custom-lockfile", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.1", - "python": "3.13", - "expected": "no-op: the CLI only reads pdm.lock", - "baselineFresh": false, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "pypi_pdm_no_lockfile" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "dependency-groups", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "dependency-groups", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "dependency-groups", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "dev", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "dev", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "dev", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "direct", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "direct", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "direct", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "extras", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "extras", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 1, - "scannedPackages": 50 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "extras", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "marker", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "marker", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "marker", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "marker-excluded", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "marker-excluded", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "multi-target", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "multi-target", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "multi-target", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "optional", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "optional", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "optional", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "pep582", - "mode": "agent", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.1", - "python": "3.13", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "pep582", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "pep582", - "mode": "vendored", - "outcome": "UNSUPPORTED", - "lockVersion": "4.5.1", - "python": "3.13", - "expected": "PDM `__pypackages__` layout: agent/vendored cannot verify the install (use hosted, or set `python.use_venv`)", - "baselineFresh": true, - "info": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "platform-linux", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "platform-linux", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "platform-windows", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "platform-windows", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": false, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "space-unicode", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "space-unicode", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "space-unicode", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "static-urls", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "static-urls", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 1, - "redirected": 1, - "scannedPackages": 49 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "static-urls", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "transitive", - "mode": "agent", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "applied": 1, - "codes": [] - } - }, - { - "pdm": "2.29.2", - "shape": "transitive", - "mode": "hosted", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "lockOnlyHosted": { - "codes": [], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18" - ], - "exit": 0, - "lockfileOnlyPackages": 5, - "redirected": 1, - "scannedPackages": 53 - }, - "applied": 1, - "codes": [ - "redirect_pypi_stale_install" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "transitive", - "mode": "vendored", - "outcome": "PASS", - "lockVersion": "4.5.1", - "python": "3.13", - "baselineFresh": true, - "info": { - "tamper": { - "installExit": 1, - "installedPatchedAnyway": false, - "mentionsHash": true - }, - "ordinaryInstall": { - "baselineFresh": true, - "exit": 0, - "lockStable": true - }, - "ordinaryInstallPatched": true, - "rollbackAfterRelockPristine": { - "exit": 0, - "failed": [], - "lockEqualsRelocked": true, - "status": "success" - }, - "rescanAfterRelock": { - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "patchInLock": true - }, - "relock": { - "crlfKept": null, - "equalsOriginal": true, - "exit": 0, - "keepsPatch": false, - "lockBytesUnchanged": false, - "pyprojectUnchanged": true, - "targetKept": true - }, - "applied": 1, - "codes": [ - "vendor_prebuilt_downloaded" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "two-versions", - "mode": "hosted", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.1", - "python": "3.13", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "lockOnlyHosted": { - "codes": [ - "redirect_pdm_refused" - ], - "crawledUrllib3": [ - "pkg:pypi/urllib3@1.26.18", - "pkg:pypi/urllib3@2.2.3" - ], - "exit": 0, - "lockfileOnlyPackages": 2, - "redirected": 0, - "scannedPackages": 50 - }, - "manifestLeftover": [], - "applied": 0, - "codes": [ - "redirect_pdm_refused" - ] - } - }, - { - "pdm": "2.29.2", - "shape": "two-versions", - "mode": "vendored", - "outcome": "REFUSED-EXPECTED", - "lockVersion": "4.5.1", - "python": "3.13", - "expected": "refused: two locked urllib3 versions (forked package)", - "baselineFresh": true, - "info": { - "manifestLeftover": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "pkg:pypi/urllib3@2.2.3?artifact_id=py3-none-any-whl" - ], - "applied": 0, - "codes": [ - "package_not_installed", - "pypi_pdm_lock_forked_package", - "vendor_fetch_unverifiable" - ] - } - } - ], - "errors": [] -} \ No newline at end of file diff --git a/docs/testing/pipenv-compatibility.md b/docs/testing/pipenv-compatibility.md index 32145f5f7..086ee8e69 100644 --- a/docs/testing/pipenv-compatibility.md +++ b/docs/testing/pipenv-compatibility.md @@ -122,67 +122,5 @@ hybrid that still carries our reference rolls back to the original entry), repeat installs and `sync` keep the in-place patch, and the out-of-tree leg requires an agent-mode scan run outside `pipenv run` to see Pipenv's venv. -## Results - - -### macOS — full matrix (18 majors × 8 shapes × 4 modes) - -CLI revision `e521093`: **470 cases, 470 pass** (103 expected refusals, 36 skipped installer limitations, 0 failing, 0 harness errors). - -| Pipenv | hosted | vendored | agent (in-project venv) | agent (out-of-tree venv) | bare CLI sees out-of-tree venv | tamper rejected (hosted / vendored) | warm venv re-installed (hosted / vendored) | relock keeps patch (hosted / vendored) | `pipenv verify` (hosted / vendored) | -| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | -| 0.2.8 | refused (redirect_pipenv_skipped) | refused (pypi_pipenv_spec_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | refused (skipped: Pipenv 0.x has no `--venv` and no WORKON_HOME placement to discover) | none | n/a / n/a | n/a / n/a | n/a / n/a | n/a / n/a | -| 3.6.2 | refused (redirect_pipenv_skipped) | refused (pypi_pipenv_spec_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | none/true | n/a / n/a | n/a / n/a | n/a / n/a | n/a / n/a | -| 4.1.4 | refused (redirect_pipenv_skipped) | refused (pypi_pipenv_spec_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | none/true | n/a / n/a | n/a / n/a | n/a / n/a | n/a / n/a | -| 5.4.2 | refused (redirect_pipenv_skipped) | refused (pypi_pipenv_spec_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | none/true | n/a / n/a | n/a / n/a | n/a / n/a | n/a / n/a | -| 6.2.9 | refused (redirect_pipenv_skipped) | refused (pypi_pipenv_spec_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | none/true | n/a / n/a | n/a / n/a | n/a / n/a | n/a / n/a | -| 7.9.10 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | refused (pypi_pipenv_installer_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | refused (skipped: Pipenv 7 cannot create its out-of-tree virtualenv in the harness image) | none | yes / n/a | false / n/a | false / n/a | 2 / n/a | -| 8.3.2 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | refused (pypi_pipenv_installer_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / n/a | false / n/a | false / n/a | 2 / n/a | -| 9.1.0 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | refused (pypi_pipenv_installer_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / n/a | false / n/a | false / n/a | 2 / n/a | -| 10.1.2 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | refused (pypi_pipenv_installer_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / n/a | false / n/a | false / n/a | 2 / n/a | -| 11.10.4 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | refused (pypi_pipenv_installer_unsupported) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / n/a | false / n/a | false / n/a | 2 / n/a | -| 2018.11.26 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / yes | false / false | false / false | 2 / 2 | -| 2020.11.15 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / yes | false / false | false / false | 2 / 2 | -| 2021.11.23 | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,marker-excluded,transitive) | pass (dev,direct,extras,marker,transitive) | true | yes / yes | false / false | false / false | 2 / 2 | -| 2022.12.19 | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,transitive) | true | yes / yes | false / false | false / false | 0 / 0 | -| 2023.12.1 | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,transitive) | true | yes / no | false / false | false / false | 0 / 0 | -| 2024.4.1 | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,transitive) | true | yes / no | false / false | false / false | 0 / 0 | -| 2025.1.3 | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,transitive) | true | yes / no | false / false | false / false | 0 / 0 | -| 2026.8.0 | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,crlf,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,marker-excluded,transitive) | pass (category,dev,direct,extras,marker,transitive) | true | yes / no | false / false | false / false | 0 / 0 | - -### Linux — release binary in a container (2018+ majors, direct shape, 4 modes) - -CLI revision `e521093`: **32 cases, 32 pass** (0 expected refusals, 0 skipped installer limitations, 0 failing, 0 harness errors). - -| Pipenv | hosted | vendored | agent (in-project venv) | agent (out-of-tree venv) | bare CLI sees out-of-tree venv | tamper rejected (hosted / vendored) | warm venv re-installed (hosted / vendored) | relock keeps patch (hosted / vendored) | `pipenv verify` (hosted / vendored) | -| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | -| 2018.11.26 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / yes | false / false | false / false | 2 / 2 | -| 2020.11.15 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / yes | false / false | false / false | 2 / 2 | -| 2021.11.23 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / yes | false / false | false / false | 2 / 2 | -| 2022.12.19 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / yes | false / false | false / false | 0 / 0 | -| 2023.12.1 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / no | false / false | false / false | 0 / 0 | -| 2024.4.1 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / no | false / false | false / false | 0 / 0 | -| 2025.1.3 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / no | false / false | false / false | 0 / 0 | -| 2026.8.0 | pass (direct) | pass (direct) | pass (direct) | pass (direct) | true | yes / no | false / false | false / false | 0 / 0 | - -### Invocation variants (`--cwd`, nested `--cwd`, symlinked project directory; direct shape, 4 modes) - -CLI revision `e521093`: **48 cases, 48 pass** (3 expected refusals, 0 skipped installer limitations, 0 failing, 0 harness errors). - -| Pipenv | invocation | hosted | vendored | agent | agent-oot | -| --- | --- | --- | --- | --- | --- | -| 11.10.4 | `--cwd ` | pass | refused (pypi_pipenv_installer_unsupported) | pass | pass | -| 11.10.4 | `--cwd` from a nested directory | pass | refused (pypi_pipenv_installer_unsupported) | pass | pass | -| 11.10.4 | symlinked project directory | pass | refused (pypi_pipenv_installer_unsupported) | pass | pass | -| 2018.11.26 | `--cwd ` | pass | pass | pass | pass | -| 2018.11.26 | `--cwd` from a nested directory | pass | pass | pass | pass | -| 2018.11.26 | symlinked project directory | pass | pass | pass | pass | -| 2022.12.19 | `--cwd ` | pass | pass | pass | pass | -| 2022.12.19 | `--cwd` from a nested directory | pass | pass | pass | pass | -| 2022.12.19 | symlinked project directory | pass | pass | pass | pass | -| 2026.8.0 | `--cwd ` | pass | pass | pass | pass | -| 2026.8.0 | `--cwd` from a nested directory | pass | pass | pass | pass | -| 2026.8.0 | symlinked project directory | pass | pass | pass | pass | - -Every `pass` cell verified the installed `urllib3/response.py` against the patch record's Git blob SHA-256 after a real Pipenv install. Columns: `warm venv re-installed` and `relock keeps patch` are measured Pipenv boundaries (see above), not requirements; `pipenv verify` exit 2 means the subcommand does not exist on that release. Per-case checks, notes and harness provenance: [`results.json`](pipenv-compatibility/results.json). - +Full run results belong with the source revision and toolchain versions in CI +artifacts or a local output directory. See the [testing guide](README.md#ci-and-results). diff --git a/docs/testing/pipenv-compatibility/results.json b/docs/testing/pipenv-compatibility/results.json deleted file mode 100644 index 755e0c006..000000000 --- a/docs/testing/pipenv-compatibility/results.json +++ /dev/null @@ -1,72046 +0,0 @@ -{ - "capturedOn": "2026-09-18", - "cliRevision": "e521093", - "runs": { - "invocations": { - "errors": [], - "platform": "macOS 15 (arm64), native CLI", - "provenance": { - "capturedAt": "2026-09-18T14:21:08.543839+00:00", - "cliRevision": "e521093", - "cliSha256": "3dedb1f8b597dec8e4ee74320a1028b1cfdab6257595185e296ed969a775c84f", - "host": "Darwin arm64", - "invocations": [ - "cwd-flag", - "subdir", - "symlink" - ], - "legacyImage": "python:3.6.15-slim", - "modes": [ - "hosted", - "vendored", - "agent", - "agent-oot" - ], - "pipenvVersions": [ - "2026.8.0", - "2022.12.19", - "2018.11.26", - "11.10.4" - ], - "shapes": [ - "direct" - ] - }, - "results": [ - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "cwd-flag", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "subdir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "symlink", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-agent-oot-cwd-flag/venvs/project-wAwCAktN-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "cwd-flag", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-agent-oot-subdir/venvs/app-4oK9yKve-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "subdir", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-agent-oot-symlink/venvs/project-RoaKTazg-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "symlink", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipe\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages stil" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipe\u2026" - } - ] - }, - "invocation": "cwd-flag", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without t\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those byte" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without t\u2026" - } - ] - }, - "invocation": "subdir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv i\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still di" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/11.10.4-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv i\u2026" - } - ] - }, - "invocation": "symlink", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "cwd-flag", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "subdir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "symlink", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "cwd-flag", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "subdir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "symlink", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-agent-oot-cwd-flag/venvs/project-uP3pTgYV-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "cwd-flag", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-agent-oot-subdir/venvs/app-ABVCOMdn-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "subdir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-agent-oot-symlink/venvs/project-Xepy222U-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "symlink", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`p\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages s" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`p\u2026" - } - ] - }, - "invocation": "cwd-flag", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without t\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those byte" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without t\u2026" - } - ] - }, - "invocation": "subdir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipen\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipen\u2026" - } - ] - }, - "invocation": "symlink", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-vendored-cwd-flag/project/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-vendored-cwd-flag/project/.ve" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-vendored-cwd-flag/project/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "cwd-flag", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so " - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "subdir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-vendored-symlink/link/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv ins\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-vendored-symlink/link/.venv/l" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2018.11.26-direct-vendored-symlink/link/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv ins\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "symlink", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "cwd-flag", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "subdir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "symlink", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-agent-oot-cwd-flag/venvs/project-4nuNhCus-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "cwd-flag", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-agent-oot-subdir/venvs/app-ePSOQNAV-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "subdir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-agent-oot-symlink/venvs/project-q4pR13ah-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "symlink", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`p\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages s" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-hosted-cwd-flag/project/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`p\u2026" - } - ] - }, - "invocation": "cwd-flag", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without t\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those byte" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without t\u2026" - } - ] - }, - "invocation": "subdir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipen\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-hosted-symlink/link/.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipen\u2026" - } - ] - }, - "invocation": "symlink", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-cwd-flag/project/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-cwd-flag/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-cwd-flag/project/.ve" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-cwd-flag/project/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "cwd-flag", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-subdir/nested/app/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so " - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "subdir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-symlink/link/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv ins\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-symlink/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-symlink/link/.venv/l" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2022.12.19-direct-vendored-symlink/link/.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv ins\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "symlink", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "cwd-flag", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "subdir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "symlink", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-agent-oot-cwd-flag/venvs/project-PAsYMkTS-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "cwd-flag", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-agent-oot-subdir/venvs/app-bSlpRn1y-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "subdir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-agent-oot-symlink/venvs/project-GgQxs9OK-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "symlink", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-hosted-cwd-flag/project/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pi\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-hosted-cwd-flag/project/.venv/lib/python3.12/site-packages st" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-hosted-cwd-flag/project/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pi\u2026" - } - ] - }, - "invocation": "cwd-flag", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without \u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those byt" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in app/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without \u2026" - } - ] - }, - "invocation": "subdir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-hosted-symlink/link/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-hosted-symlink/link/.venv/lib/python3.12/site-packages still " - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-hosted-symlink/link/.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv\u2026" - } - ] - }, - "invocation": "symlink", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-vendored-cwd-flag/project/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-vendored-cwd-flag/project/.venv" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-vendored-cwd-flag/project/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "cwd-flag", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching th\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in app/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching th\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "subdir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-vendored-symlink/link/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv inst\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-vendored-symlink/link/.venv/lib" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in /private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-inv/captures/2026.8.0-direct-vendored-symlink/link/.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv inst\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "symlink", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - } - ] - }, - "linux": { - "errors": [], - "platform": "Debian 12 (arm64) container, release CLI", - "provenance": { - "capturedAt": "2026-09-18T14:23:15.899056+00:00", - "cliRevision": "e521093", - "cliSha256": "dea3c3fdf39512216dc382aaca5f07ce88eeeef1b7cf38683068956a71c42c04", - "host": "Linux aarch64", - "invocations": [ - "in-dir" - ], - "legacyImage": "python:3.6.15-slim", - "modes": [ - "hosted", - "vendored", - "agent", - "agent-oot" - ], - "pipenvVersions": [ - "2018.11.26", - "2020.11.15", - "2021.11.23", - "2022.12.19", - "2023.12.1", - "2024.4.1", - "2025.1.3", - "2026.8.0" - ], - "shapes": [ - "direct" - ] - }, - "results": [ - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2018.11.26-direct-agent-oot/venvs/project-mF2HGUnO-/out/tools/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2020.11.15-direct-agent-oot/venvs/project-69ycha_K-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2021.11.23-direct-agent-oot/venvs/project-Gx4HxHSi-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2022.12.19-direct-agent-oot/venvs/project-0g61h4-J-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///out/final/captures/2022.12.19-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2023.12.1-direct-agent-oot/venvs/project-PVj1ALdm-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2024.4.1-direct-agent-oot/venvs/project-Q1XxEGgw-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2025.1.3-direct-agent-oot/venvs/project-ZiSwsYIx-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/out/final/captures/2026.8.0-direct-agent-oot/venvs/project-X5QLZv1w-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - } - ] - }, - "macos": { - "errors": [], - "platform": "macOS 15 (arm64), native CLI; Pipenv 0.2.8-11.10.4 inside python:3.6.15-slim", - "provenance": { - "capturedAt": "2026-09-18T14:21:06.520127+00:00", - "cliRevision": "e521093", - "cliSha256": "3dedb1f8b597dec8e4ee74320a1028b1cfdab6257595185e296ed969a775c84f", - "host": "Darwin arm64", - "invocations": [ - "in-dir" - ], - "legacyImage": "python:3.6.15-slim", - "mergedFrom": [ - { - "path": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-a/summary.json", - "provenance": { - "capturedAt": "2026-09-18T14:45:17.630925+00:00", - "cliRevision": "e521093", - "cliSha256": "3dedb1f8b597dec8e4ee74320a1028b1cfdab6257595185e296ed969a775c84f", - "host": "Darwin arm64", - "invocations": [ - "in-dir" - ], - "legacyImage": "python:3.6.15-slim", - "modes": [ - "agent" - ], - "pipenvVersions": [ - "0.2.8" - ], - "shapes": [ - "dev" - ] - } - }, - { - "path": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-b/summary.json", - "provenance": { - "capturedAt": "2026-09-18T14:45:31.872148+00:00", - "cliRevision": "e521093", - "cliSha256": "3dedb1f8b597dec8e4ee74320a1028b1cfdab6257595185e296ed969a775c84f", - "host": "Darwin arm64", - "invocations": [ - "in-dir" - ], - "legacyImage": "python:3.6.15-slim", - "modes": [ - "agent-oot" - ], - "pipenvVersions": [ - "5.4.2" - ], - "shapes": [ - "dev", - "direct" - ] - } - }, - { - "path": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-c/summary.json", - "provenance": { - "capturedAt": "2026-09-18T14:45:49.934581+00:00", - "cliRevision": "e521093", - "cliSha256": "3dedb1f8b597dec8e4ee74320a1028b1cfdab6257595185e296ed969a775c84f", - "host": "Darwin arm64", - "invocations": [ - "in-dir" - ], - "legacyImage": "python:3.6.15-slim", - "modes": [ - "agent-oot" - ], - "pipenvVersions": [ - "4.1.4" - ], - "shapes": [ - "transitive" - ] - } - }, - { - "path": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-d/summary.json", - "provenance": { - "capturedAt": "2026-09-18T14:47:07.046287+00:00", - "cliRevision": "e521093", - "cliSha256": "3dedb1f8b597dec8e4ee74320a1028b1cfdab6257595185e296ed969a775c84f", - "host": "Darwin arm64", - "invocations": [ - "in-dir" - ], - "legacyImage": "python:3.6.15-slim", - "modes": [ - "hosted", - "vendored" - ], - "pipenvVersions": [ - "2023.12.1", - "2024.4.1", - "2025.1.3", - "2026.8.0" - ], - "shapes": [ - "marker-excluded" - ] - } - } - ], - "modes": [ - "hosted", - "vendored", - "agent", - "agent-oot" - ], - "pipenvVersions": [ - "0.2.8", - "3.6.2", - "4.1.4", - "5.4.2", - "6.2.9", - "7.9.10", - "8.3.2", - "9.1.0", - "10.1.2", - "11.10.4", - "2018.11.26", - "2020.11.15", - "2021.11.23", - "2022.12.19", - "2023.12.1", - "2024.4.1", - "2025.1.3", - "2026.8.0" - ], - "shapes": [ - "direct", - "dev", - "category", - "marker", - "marker-excluded", - "extras", - "transitive", - "crlf" - ] - }, - "results": [ - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "dev", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x has no `--venv` and no WORKON_HOME placement to discover", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "direct", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x has no `--venv` and no WORKON_HOME placement to discover", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 0 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x cannot stamp the transitive Pipfile's content hash", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x cannot stamp the transitive Pipfile's content hash", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x cannot stamp the transitive Pipfile's content hash", - "info": {}, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x cannot stamp the transitive Pipfile's content hash", - "info": {}, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "0.2.8", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/10.1.2-dev-agent-oot/venvs/project-le2Kar3x", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/10.1.2-direct-agent-oot/venvs/project-Vi8Y6k5P", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/10.1.2-extras-agent-oot/venvs/project-Hdy1kYbO", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/10.1.2-marker-agent-oot/venvs/project-mSh7SIOh", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": false - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/10.1.2-transitive-agent-oot/venvs/project-bkGR-pKq", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "10.1.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/11.10.4-dev-agent-oot/venvs/project-EuBgobiP-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/11.10.4-direct-agent-oot/venvs/project-p4uodGuH-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/11.10.4-extras-agent-oot/venvs/project-c6zJSbVZ-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "extras", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/11.10.4-marker-agent-oot/venvs/project-TLOj7X4t-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker", - "supported": false - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/11.10.4-transitive-agent-oot/venvs/project-TPz-ubcN-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/legacy-tools/11.10.4/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "11.10.4", - "pipfileSpec": 6, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2018.11.26-dev-agent-oot/venvs/project-rvumQJR7-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2018.11.26-direct-agent-oot/venvs/project-rRD3ZqKE-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2018.11.26-extras-agent-oot/venvs/project-oO1dqUUx-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2018.11.26-marker-agent-oot/venvs/project-p-7NMJlC-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2018.11.26-transitive-agent-oot/venvs/project-uDoo2NrU-/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/pipenv-matrix/tools/2018.11.26/bin/python", - "ootVenvNameMatchesWorkon": false, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2018.11.26", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2020.11.15-dev-agent-oot/venvs/project-WBeaWwaZ-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2020.11.15-direct-agent-oot/venvs/project-_BmhyZkL-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2020.11.15-extras-agent-oot/venvs/project-usOBprOu-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2020.11.15-marker-agent-oot/venvs/project-P5aQHRYw-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2020.11.15-transitive-agent-oot/venvs/project-RHhZLWm9-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2020.11.15", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2021.11.23-dev-agent-oot/venvs/project-jotSn62P-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2021.11.23-direct-agent-oot/venvs/project-7YJlTv1q-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2021.11.23-extras-agent-oot/venvs/project-O9SEazj5-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2021.11.23-marker-agent-oot/venvs/project-hximekEn-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2021.11.23-transitive-agent-oot/venvs/project-avsbOHLg-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2021.11.23", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-category-agent-oot/venvs/project-VPPSdrXF-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-category-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-dev-agent-oot/venvs/project-Oe79nwd5-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-dev-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-direct-agent-oot/venvs/project-xrFY7ef0-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "tamper": { - "expectsReject": false, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-extras-agent-oot/venvs/project-fj5TX4um-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 1, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3#egg=urllib3[socks]" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl[socks]" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-marker-agent-oot/venvs/project-3kF_SAjR-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3 ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-marker-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3 ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-marker-excluded-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-transitive-agent-oot/venvs/project-4b8AKKsv-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#egg=urllib3" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "file:///private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2022.12.19-transitive-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ] - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so th" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.8/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the P\u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2022.12.19", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2023.12.1-category-agent-oot/venvs/project-xEc6rJSO-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2023.12.1-dev-agent-oot/venvs/project-PtTzFqFB-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2023.12.1-direct-agent-oot/venvs/project-0UeNFdlr-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2023.12.1-extras-agent-oot/venvs/project-xkdemobK-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'", - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2023.12.1-marker-agent-oot/venvs/project-DDR4ZCp_-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2023.12.1-transitive-agent-oot/venvs/project-7-es0NIB-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2023.12.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2024.4.1-category-agent-oot/venvs/project--fnruCrf-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2024.4.1-dev-agent-oot/venvs/project-xsC0u6dL-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2024.4.1-direct-agent-oot/venvs/project-Nlq3YoNQ-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2024.4.1-extras-agent-oot/venvs/project-Jsn3tijM-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'", - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2024.4.1-marker-agent-oot/venvs/project-Vj1hhlg6-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2024.4.1-transitive-agent-oot/venvs/project-yDGP0fUF-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2024.4.1", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2025.1.3-category-agent-oot/venvs/project-yAeGV-DD-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2025.1.3-dev-agent-oot/venvs/project-Fdze9eCY-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2025.1.3-direct-agent-oot/venvs/project-UDidtARQ-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2025.1.3-extras-agent-oot/venvs/project-wKfQ5P1A-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'", - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2025.1.3-marker-agent-oot/venvs/project-Ua-x4uOM-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2025.1.3-transitive-agent-oot/venvs/project-sqNtW4tO-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2025.1.3", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2026.8.0-category-agent-oot/venvs/project-jp5oYRPn-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "tests", - "urllib3" - ] - ], - "rewritten": [ - [ - "tests", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "tests" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "category", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2026.8.0-dev-agent-oot/venvs/project-XetQvjsN-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2026.8.0-direct-agent-oot/venvs/project-QZo5Ld-I-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Listed": true, - "venvDistributions": 3 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2026.8.0-extras-agent-oot/venvs/project-Pb7pwpA2-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "extras": [ - "socks" - ], - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'", - "path": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Listed": true, - "venvDistributions": 2 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2026.8.0-marker-agent-oot/venvs/project-Z_FGngEQ-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version < '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version > '4'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "hybridRelock": true, - "lockKeptRelocked": false, - "lockRestoredOriginal": true, - "referenceLeft": false - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 6, - "urllib3Listed": true, - "venvDistributions": 6 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/2026.8.0-transitive-agent-oot/venvs/project-tFo0iv7w-python", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6 ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.12/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without to\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasVendoredRef": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsVendorState": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "file", - "got": [ - "file" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [ - "already_vendored", - "vendor_fetched_missing" - ], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "requirementsExport": { - "exit": 0, - "exportsPatchRef": true, - "urllib3Line": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl ; python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "file": "./.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl", - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "sourceKeys": [ - "file" - ], - "staleInstallWarned": { - "codes": [ - "pypi_pipenv_stale_install", - "vendor_integrity_unverified", - "vendor_prebuilt_downloaded" - ], - "detail": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so t" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 0 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - }, - "sync": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "Pipenv does not consistently enforce the hashes recorded on file-ref lock entries (2018\u20132022 verify them, 2023+ install a local wheel without checking), so the vendored wheel is protected only by the committed wheel itself; `socket-patch vex --product ` verifies the installed files against the patch record" - }, - { - "action": "skipped", - "errorCode": "pypi_pipenv_stale_install", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl: the UNPATCHED upstream release is still installed in ./.venv/lib/python3.12/site-packages. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the wired Pipfile.lock only protects fresh installs. Reinstall it from the lock without touching the \u2026" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "2026.8.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/3.6.2-dev-agent-oot/venvs/project-H7fL1xTY", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/3.6.2-direct-agent-oot/venvs/project-SjHJBH5g", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/3.6.2-transitive-agent-oot/venvs/project-R9KbIlov", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "3.6.2", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/4.1.4-dev-agent-oot/venvs/project-156NY79G", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/4.1.4-direct-agent-oot/venvs/project-S8Z-YEC3", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "direct", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-c/captures/4.1.4-transitive-agent-oot/venvs/project-hOJKMBk9", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is None; only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "4.1.4", - "pipfileSpec": null, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-b/captures/5.4.2-dev-agent-oot/venvs/project-HHSeGvEK", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "dev", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final-fix-b/captures/5.4.2-direct-agent-oot/venvs/project-75euv67j", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "direct", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/5.4.2-transitive-agent-oot/venvs/project-PWzNFRQ1", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(1); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "5.4.2", - "pipfileSpec": 1, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/6.2.9-dev-agent-oot/venvs/project-WccTvFLA", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "dev", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/6.2.9-direct-agent-oot/venvs/project-96LD91ty", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "direct", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "direct", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "extras", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "extras", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker", - "supported": false - }, - { - "checks": {}, - "expected": "skipped: Pipenv 0.x\u20136.x mishandle inline-table (markers/extras) Pipfile entries", - "info": {}, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/6.2.9-transitive-agent-oot/venvs/project-NnL-gs-7", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": true, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (redirect_pipenv_skipped)", - "info": { - "applied": 0, - "dryRun": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 0, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "redirect_pipenv_skipped" - ], - "exit": 0 - }, - "rollbackHarmless": { - "exit": 1 - }, - "scanExit": 0, - "warnings": [ - { - "code": "redirect_pipenv_skipped", - "detail": "only pipfile-spec 6 supports patch file references" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-lock-spec (pypi_pipenv_spec_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported", - "vendor_fetched_missing" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_spec_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "Pipfile.lock _meta.pipfile-spec is Some(3); only spec 6 locks are fixture-tested", - "errorCode": "pypi_pipenv_spec_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "6.2.9", - "pipfileSpec": 3, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 7 cannot create its out-of-tree virtualenv in the harness image", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "dev", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 7 cannot create its out-of-tree virtualenv in the harness image", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 7 cannot create its out-of-tree virtualenv in the harness image", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "extras", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "extras", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 7 cannot create its out-of-tree virtualenv in the harness image", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker", - "supported": false - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": {}, - "expected": "skipped: Pipenv 7 cannot create its out-of-tree virtualenv in the harness image", - "info": {}, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "7.9.10", - "pipfileSpec": 6, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/8.3.2-dev-agent-oot/venvs/project-Iq5OMDdg", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/8.3.2-direct-agent-oot/venvs/project-RW6cQyoM", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/8.3.2-extras-agent-oot/venvs/project-qCX_4SXE", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "extras", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/8.3.2-marker-agent-oot/venvs/project-tk6-Ud0l", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker", - "supported": false - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/8.3.2-transitive-agent-oot/venvs/project-iGJfHZ9t", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "8.3.2", - "pipfileSpec": 6, - "shape": "transitive", - "supported": false - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "crlfPreserved": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "crlf", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "crlf", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/9.1.0-dev-agent-oot/venvs/project-9NPbAK7d", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "develop", - "urllib3" - ] - ], - "rewritten": [ - [ - "develop", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "develop" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "dev", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/9.1.0-direct-agent-oot/venvs/project-zwilhVJE", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRestoredAfterTamper": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "tamperRejected": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperRejected": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "direct", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 5, - "urllib3Listed": true, - "venvDistributions": 5 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/9.1.0-extras-agent-oot/venvs/project-VoTeUWTM", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 2 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 2 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "extras", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Listed": true, - "venvDistributions": 4 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/9.1.0-marker-agent-oot/venvs/project-KTlWVSq1", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version < '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker", - "supported": false - }, - { - "checks": { - "excludedStaysAbsent": true, - "lockUntouched": true, - "nothingApplied": true - }, - "expected": "marker excludes urllib3: nothing installed, nothing to patch", - "info": { - "nothingApplied": { - "applied": 0, - "exit": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "excludedStaysAbsent": true, - "expectedSourceKey": true, - "freshCloneKeepsExcluded": true, - "freshCloneLockUnchanged": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "excludedStaysAbsent": { - "urllib3/response.py": null - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneKeepsExcluded": { - "exit": 0 - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 1 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "markers": "python_version > '4'", - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 1, - "statements": 0 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 1 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "marker-excluded", - "supported": false - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsLock": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "appliedExactlyOne": { - "applied": 1, - "patches": [ - { - "action": "added", - "description": "", - "exportedAt": "Wed, 29 Jul 2026 20:20:47 GMT", - "license": "", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "severity": "HIGH", - "tier": "free", - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vulnerabilities": [ - { - "cves": [ - "CVE-2025-66418" - ], - "description": "## Impact\n\nurllib3 supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., `Content-Encoding: gzip, zstd`).\n\nHowever, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data.\n\n\n## Affected \u2026", - "id": "GHSA-gm62-xv2j-4w53", - "severity": "HIGH", - "summary": "urllib3 allows an unbounded number of links in the decompression chain" - } - ] - } - ], - "status": "success" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 1, - "statements": 0 - } - }, - "invocation": "in-dir", - "mode": "agent", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "bareScanSeesPipenvVenv": true, - "installedBytesPatched": true, - "lockUntouched": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "scanApplied": true, - "survivesRepeatInstall": true - }, - "expected": null, - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "bareScanSeesPipenvVenv": { - "exit": 0, - "foreignInterpreterHit": false, - "found": 1, - "paths": [], - "scannedPackages": 8, - "urllib3Listed": true, - "venvDistributions": 8 - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "ootVenv": "/private/tmp/claude-501/-Users-mikolalysenko-Projects-socket-patch/56821dee-aa37-470e-81d6-869966c18cc1/scratchpad/matrix-final/captures/9.1.0-transitive-agent-oot/venvs/project-xNX_V925", - "ootVenvNameMatchesWorkon": true, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "scanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "invocation": "in-dir", - "mode": "agent-oot", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "allCategoriesRewritten": true, - "appliedExactlyOne": true, - "dryRunParity": true, - "expectedSourceKey": true, - "freshCloneInstallsPatch": true, - "freshCloneLockUnchanged": true, - "installedBytesPatched": true, - "lockHasPatchUrl": true, - "lockOnlyApplies": true, - "lockOnlyRescanGreen": true, - "lockRewritten": true, - "lockStillJson": true, - "lockUnchangedByInstall": true, - "markersExtrasPreserved": true, - "metaUnchanged": true, - "noCrlfIntroduced": true, - "pipenvInstallExit0": true, - "pipfileUnchanged": true, - "pipfileUnchangedByInstall": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackAfterRelockRetires": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPipfile": true, - "rollbackRestoresLockBytes": true, - "staleInstallWarned": true, - "warmInstallReplacesUpstream": false - }, - "expected": null, - "info": { - "allCategoriesRewritten": { - "pristine": [ - [ - "default", - "urllib3" - ] - ], - "rewritten": [ - [ - "default", - "urllib3" - ] - ] - }, - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "exit": 0, - "status": "success", - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "expectedSourceKey": { - "expected": "path", - "got": [ - "path" - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockOnly": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 1, - "codes": [], - "exit": 0, - "lockfileOnlyPackages": 5 - }, - "lockOnlyRescanGreen": { - "codes": [], - "exit": 0, - "status": "success" - }, - "relock": { - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pipfileUnchanged": true - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rewrittenEntries": [ - { - "entry": { - "hashes": [ - "sha256:ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - ], - "path": "https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6" - }, - "key": "urllib3", - "section": "default" - } - ], - "rollbackAfterRelockRetires": { - "cleared": true, - "envelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "status": "success", - "vendoredReverted": [] - }, - "exit": 0, - "lockKeptRelocked": true - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "sourceKeys": [ - "path" - ], - "staleInstallWarned": { - "codes": [ - "redirect_pypi_stale_install" - ], - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes)" - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "verify": { - "exit": 2 - }, - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstallReplacesUpstream": { - "install": { - "exit": 0, - "patched": false - } - }, - "warmReinstalled": { - "install": { - "exit": 0, - "patched": false - } - }, - "warnings": [ - { - "code": "redirect_pypi_stale_install", - "detail": "pkg:pypi/urllib3@1.26.18 was redirected to a hosted patch, but installed files in ./.venv/lib/python3.8/site-packages still differ from the patched hashes. Pipenv does not reinstall a release that is already present (`pipenv install`, `pipenv install --deploy` and `pipenv sync` all keep those bytes), so the rewritten Pipfile.lock only protects fresh installs. Reinstall it from the lock without tou\u2026" - } - ] - }, - "invocation": "in-dir", - "mode": "hosted", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": true - }, - { - "checks": { - "dryRunParity": false, - "lockOnlyApplies": false, - "lockUnchanged": true, - "noLedger": true, - "pipfileUnchanged": true, - "refusedWithCode": true, - "rollbackHarmless": true - }, - "expected": "refused: unsupported-vendored-installer (pypi_pipenv_installer_unsupported)", - "info": { - "applied": 0, - "dryRun": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "dryRunParity": { - "applied": 1, - "exit": 0, - "untouched": true - }, - "lockOnly": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "lockOnlyApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1, - "lockfileOnlyPackages": 5 - }, - "refusedWithCode": { - "applied": 0, - "codes": [ - "pypi_pipenv_installer_unsupported" - ], - "exit": 1 - }, - "rollbackHarmless": { - "exit": 0 - }, - "scanExit": 1, - "warnings": [ - { - "action": "failed", - "error": "vendored wheel references require Pipenv 2018 or later; upgrade Pipenv or use hosted mode", - "errorCode": "pypi_pipenv_installer_unsupported", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - } - ] - }, - "invocation": "in-dir", - "mode": "vendored", - "passed": true, - "pipenv": "9.1.0", - "pipfileSpec": 6, - "shape": "transitive", - "supported": false - } - ] - } - } -} diff --git a/docs/testing/poetry-compatibility.md b/docs/testing/poetry-compatibility.md index 288480710..c59d7fcca 100644 --- a/docs/testing/poetry-compatibility.md +++ b/docs/testing/poetry-compatibility.md @@ -25,9 +25,10 @@ managers. Both modes retain the package version, dependencies, groups, markers, extras and the pyproject `content-hash`; no pyproject edit is required. A repeated -scan leaves the lock unchanged. Rollback restores the recorded original -fragments — one per patch (plus the integrity-table entry on legacy formats), -so either of two patches can be rolled back first and unrelated edits survive. +scan leaves the lock unchanged. Vendored rollback restores the recorded original +fragments. Hosted rollback +resolves upstream registry entries; it has no replay ledger or guarantee of the +original byte layout. Both preserve unrelated entries. Refused before any write: a `[[package]]` listed at several versions (marker fork), a user-authored `[package.source]` on another origin (an earlier Socket URL for the same wheel is superseded in place, e.g. after a grant-token @@ -95,11 +96,9 @@ Other measured details: `files` the rewrite added for Poetry ≥ 1.2's hash check; a lock relocked by 1.1 and then installed by 1.2+ installs the hosted wheel unverified. Re-run `socket-patch scan --mode hosted` after relocking on those releases: the - re-scan restores the entry and rebases the ledger's recorded edits onto the - relocked text (pristine → current, never an appended chain), so `rollback` - still lands on the pristine lock afterwards. A relocked-but-not-rescanned - lock is refused by `rollback` (its recorded fragments match nothing) rather - than reported as already reverted. + re-scan restores the source and integrity fields. In v5, hosted rollback + reconstructs upstream metadata and may refuse a drifted lock; it does not replay + pre-scan fragments. - Poetry 0.12 and 1.0 resolve a relative `type = "file"` path against the shell's working directory, not the project root; run `poetry install` from the project root on those releases. @@ -172,38 +171,5 @@ utils::poetry_lock vendor::pypi_poetry` and `cargo test -p socket-patch-core `crates/socket-patch-core/tests/fixtures/poetry//` are the harness's `original/` inputs (same pyproject, same `content-hash`). -## Results - - -| Poetry | hosted | vendored | agent (in-project venv) | agent (`poetry run`, out-of-tree venv) | tamper rejected (hosted / vendored) | warm venv re-installed (hosted / vendored) | relock keeps patch (hosted / vendored) | lock-only vendored | -| --- | --- | --- | --- | --- | --- | --- | --- | --- | -| 0.12.17 | refused (0.x ignores URL sources) | pass (crlf,direct,populated) | pass (direct) | n/a | n/a / no | n/a / false | n/a / false | refused | -| 1.0.10 | pass (crlf,direct,populated) | pass (crlf,direct,populated) | pass (direct) | pass (direct) | yes / no | false / false | false / false | refused (crlf), refused (direct), yes (populated) | -| 1.1.15 | pass (crlf,direct,populated) | pass (crlf,direct,populated) | pass (direct) | pass (direct) | yes / no | false / false | true / true | refused (crlf), refused (direct), yes (populated) | -| 1.2.2 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / no | false / false | true / true | yes | -| 1.3.2 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / no | false / false | true / true | yes | -| 1.4.2 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 1.5.1 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 1.6.1 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 1.7.1 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 1.8.5 | pass (crlf,direct) | pass (crlf,direct) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 2.0.1 | pass (crlf,direct,pep621) | pass (crlf,direct,pep621) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 2.1.4 | pass (crlf,direct,pep621) | pass (crlf,direct,pep621) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 2.2.1 | pass (crlf,direct,pep621) | pass (crlf,direct,pep621) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 2.3.4 | pass (crlf,direct,pep621) | pass (crlf,direct,pep621) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | -| 2.4.3 | pass (crlf,direct,pep621) | pass (crlf,direct,pep621) | pass (direct) | pass (direct) | yes / yes | true / true | true / true | yes | - - -Captured 2026-09-17 on macOS arm64 against the fix-branch head; 108 cases, -all passing (the `pass`/`refused` cells are the asserted outcomes; the -`tamper` / `warm venv` / `relock` / `lock-only vendored` columns are the -measured installer facts the sections above describe). The -[machine-readable results](poetry-compatibility/results.json) carry every -check, the CLI envelopes' relevant fields and the per-step exit codes. -`poetry lock` on 0.12 / 1.0 is bare (no `--no-update`), hence -`relock keeps patch = false` there; `lock-only vendored = refused` on 0.12 and -on the unpopulated 1.0/1.1 fixtures (`urllib3 = []`) because those locks name -no wheel hash. The companion SBOM annotation work and its own capture set live -in SocketDev/depscan (`tools/pipeline/poetry-patch-backtest.py`). +Full run results belong with the source revision and toolchain versions in CI +artifacts or a local output directory. See the [testing guide](README.md#ci-and-results). diff --git a/docs/testing/poetry-compatibility/results.json b/docs/testing/poetry-compatibility/results.json deleted file mode 100644 index d85d89157..000000000 --- a/docs/testing/poetry-compatibility/results.json +++ /dev/null @@ -1,11925 +0,0 @@ -{ - "errors": [], - "provenance": { - "capturedAt": "2026-09-17T20:22:39.127492+00:00", - "cliRevision": "75d49ac", - "cliSha256": "40a16bf5f5fe0f58e738710b88283a6dd412de0e6e23f958b324d9debacf201d", - "host": "Darwin arm64", - "modes": [ - "hosted", - "vendored", - "agent", - "agent-oot", - "setup" - ], - "note": "Single harness run on the fix-branch head; the Poetry 1.1.15 `setup` case was re-run alone after its first attempt hit Poetry <= 1.1's shared HTTP-cache lock (the CLI-spawned `poetry lock` now also gets the case-isolated HOME).", - "poetryVersions": [ - "0.12.17", - "1.0.10", - "1.1.15", - "1.2.2", - "1.3.2", - "1.4.2", - "1.5.1", - "1.6.1", - "1.7.1", - "1.8.5", - "2.0.1", - "2.1.4", - "2.2.1", - "2.3.4", - "2.4.3" - ], - "shapes": [ - "direct", - "populated", - "crlf", - "pep621" - ] - }, - "results": [ - { - "checks": { - "lockUnchanged": true, - "noLedger": true, - "pyprojectUnchanged": true, - "refusedWithWarning": true - }, - "expected": "refused: Poetry 0.x ignores URL sources", - "info": { - "applied": 0, - "refusedWithWarning": [ - { - "code": "redirect_poetry_lock_unsupported", - "detail": "poetry.lock: Poetry 0.x ignores URL sources; hosted patches require Poetry >= 1.0" - } - ], - "scanExit": 0, - "warnings": [ - { - "code": "redirect_poetry_lock_unsupported", - "detail": "poetry.lock: Poetry 0.x ignores URL sources; hosted patches require Poetry >= 1.0" - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "0.12.17", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n - Installing poetry-patch-fixture (0.1.0)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNothing to install or update\n\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNothing to install or update\n\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "0.12.17", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "0.12.17", - "shape": "direct" - }, - { - "checks": { - "lockUnchanged": true, - "noLedger": true, - "pyprojectUnchanged": true, - "refusedWithWarning": true - }, - "expected": "refused: Poetry 0.x ignores URL sources", - "info": { - "applied": 0, - "refusedWithWarning": [ - { - "code": "redirect_poetry_lock_unsupported", - "detail": "poetry.lock: Poetry 0.x ignores URL sources; hosted patches require Poetry >= 1.0" - } - ], - "scanExit": 0, - "warnings": [ - { - "code": "redirect_poetry_lock_unsupported", - "detail": "poetry.lock: Poetry 0.x ignores URL sources; hosted patches require Poetry >= 1.0" - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "0.12.17", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n - Installing poetry-patch-fixture (0.1.0)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNothing to install or update\n\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNothing to install or update\n\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "0.12.17", - "shape": "direct" - }, - { - "checks": { - "lockUnchanged": true, - "noLedger": true, - "pyprojectUnchanged": true, - "refusedWithWarning": true - }, - "expected": "refused: Poetry 0.x ignores URL sources", - "info": { - "applied": 0, - "refusedWithWarning": [ - { - "code": "redirect_poetry_lock_unsupported", - "detail": "poetry.lock: Poetry 0.x ignores URL sources; hosted patches require Poetry >= 1.0" - } - ], - "scanExit": 0, - "warnings": [ - { - "code": "redirect_poetry_lock_unsupported", - "detail": "poetry.lock: Poetry 0.x ignores URL sources; hosted patches require Poetry >= 1.0" - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "0.12.17", - "shape": "populated" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n - Installing poetry-patch-fixture (0.1.0)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNothing to install or update\n\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNothing to install or update\n\n - Installing poetry-patch-fixture (0.1.0)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "0.12.17", - "shape": "populated" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel. Poetry 1.0 installs through pip: pip 22.3\u201323.0 misparse the hash fragment and refuse the install (fail-closed) \u2014 use pip <= 22.2 or >= 23.1 in the virtualenv." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6&)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6&)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel. Poetry 1.0 installs through pip: pip 22.3\u201323.0 misparse the hash fragment and refuse the install (fail-closed) \u2014 use pip <= 22.2 or >= 23.1 in the virtualenv." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.0.10", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.0.10", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.0.10", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 3, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 3 - }, - "ootVenv": "/matrix-final2/captures/1.0.10-direct-agent-oot/venvs/poetry-patch-fixture-OOp1MSO--py3.8", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.0.10", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel. Poetry 1.0 installs through pip: pip 22.3\u201323.0 misparse the hash fragment and refuse the install (fail-closed) \u2014 use pip <= 22.2 or >= 23.1 in the virtualenv." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6&)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6&)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel. Poetry 1.0 installs through pip: pip 22.3\u201323.0 misparse the hash fragment and refuse the install (fail-closed) \u2014 use pip <= 22.2 or >= 23.1 in the virtualenv." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.0.10", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.0.10", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel. Poetry 1.0 installs through pip: pip 22.3\u201323.0 misparse the hash fragment and refuse the install (fail-closed) \u2014 use pip <= 22.2 or >= 23.1 in the virtualenv." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6&)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl#sha256=ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6&)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel. Poetry 1.0 installs through pip: pip 22.3\u201323.0 misparse the hash fragment and refuse the install (fail-closed) \u2014 use pip <= 22.2 or >= 23.1 in the virtualenv." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.0.10", - "shape": "populated" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 .socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": false, - "pyprojectUnchanged": true, - "tail": "Updating dependencies\nResolving dependencies...\n\nWriting lock file\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.0.10", - "shape": "populated" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanAfterRelockApplies": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n\nWriting lock file\n" - }, - "rescanAfterRelock": { - "applied": 1, - "exit": 0, - "lockChanged": true - }, - "rescanAfterRelockApplies": { - "applied": 1, - "exit": 0 - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.1.15", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.1.15-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.1.15-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.1.15", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.1.15", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 4 - }, - "ootVenv": "/matrix-final2/captures/1.1.15-direct-agent-oot/venvs/poetry-patch-fixture-Ynsj_tRb-py3.8", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.1.15", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanAfterRelockApplies": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n\nWriting lock file\n" - }, - "rescanAfterRelock": { - "applied": 1, - "exit": 0, - "lockChanged": true - }, - "rescanAfterRelockApplies": { - "applied": 1, - "exit": 0 - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.1.15", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": false, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.1.15-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "lockOnlyVendorApplies": { - "applied": 0, - "codes": [ - "package_not_installed", - "vendor_fetch_unverifiable" - ], - "exit": 1 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.1.15-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.1.15", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanAfterRelockApplies": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n\nWriting lock file\n" - }, - "rescanAfterRelock": { - "applied": 1, - "exit": 0, - "lockChanged": true - }, - "rescanAfterRelockApplies": { - "applied": 1, - "exit": 0 - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.1.15", - "shape": "populated" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.1.15-populated-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": null - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.1.15-populated-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nNo dependencies to install or update\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.1.15", - "shape": "populated" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanAfterRelockApplies": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n\nWriting lock file\n" - }, - "rescanAfterRelock": { - "applied": 1, - "exit": 0, - "lockChanged": true - }, - "rescanAfterRelockApplies": { - "applied": 1, - "exit": 0 - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.2.2", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.2.2-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.2.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.2.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.2.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.2.2", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.2.2", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 4 - }, - "ootVenv": "/matrix-final2/captures/1.2.2-direct-agent-oot/venvs/poetry-patch-fixture--o8xsesc-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.2.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanAfterRelockApplies": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": false, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n\nWriting lock file\n" - }, - "rescanAfterRelock": { - "applied": 1, - "exit": 0, - "lockChanged": true - }, - "rescanAfterRelockApplies": { - "applied": 1, - "exit": 0 - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.2.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.2.2-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.2.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.2.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.2.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.2.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.3.2", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.3.2-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.3.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.3.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.3.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.3.2", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.3.2", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 4 - }, - "ootVenv": "/matrix-final2/captures/1.3.2-direct-agent-oot/venvs/poetry-patch-fixture-nqgm3NcM-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.3.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "code": "redirect_poetry_stale_install_risk", - "detail": "poetry.lock was written by Poetry < 1.4, which does not replace an already-installed package at the same version: an existing virtualenv keeps the upstream urllib3 until it is recreated (or the package is `pip uninstall`ed) before `poetry install`; fresh installs pick up the patched wheel." - } - ] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.3.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": false - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.3.2-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "pypi_poetry_integrity_unverified", - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.3.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "tamperBehaviorAsDocumented": { - "expectsReject": false, - "installExit": 0, - "installedPatchedAnyway": true - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": false, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.3.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": false, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.3.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "pypi_poetry_integrity_unverified", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "poetry.lock was written by Poetry < 1.4: that installer does not verify local wheel hashes (the committed wheel bytes are the protection \u2014 review them) and does not replace an already-installed package at the same version \u2014 upgrade to Poetry >= 1.4, or recreate the virtualenv (or `pip uninstall` the package) before `poetry install`" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.3.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.4.2", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.4.2-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.4.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.4.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.4.2-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.4.2", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.4.2", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 4, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 4 - }, - "ootVenv": "/matrix-final2/captures/1.4.2-direct-agent-oot/venvs/poetry-patch-fixture-7SNtuRHk-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.4.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.4.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.4.2-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.4.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.4.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.4.2-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.4.2", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.5.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.5.1-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.5.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.5.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.5.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.5.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.5.1", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/1.5.1-direct-agent-oot/venvs/poetry-patch-fixture-_zoUJMnU-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.5.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.5.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.5.1-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "lock --check", - "exit": 0, - "tail": "poetry.lock is consistent with pyproject.toml.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.5.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.5.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.5.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.5.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.6.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.6.1-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.6.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.6.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.6.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.6.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.6.1", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/1.6.1-direct-agent-oot/venvs/poetry-patch-fixture-3oGutE4e-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.6.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.6.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.6.1-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.6.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.6.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.6.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.6.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.7.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.7.1-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.7.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.7.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "\u2022 Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.7.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.7.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.7.1", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/1.7.1-direct-agent-oot/venvs/poetry-patch-fixture-h-NPhXP2-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.7.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n \u2022 Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.7.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.7.1-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n \u2022 Installing urllib3 (1.26.18 /matrix-final2/captures/1.7.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.7.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.7.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.7.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.8.5", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/1.8.5-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/1.8.5-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.8.5-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.8.5-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.8.5", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "1.8.5", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/1.8.5-direct-agent-oot/venvs/poetry-patch-fixture-A0_pGI6P-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "1.8.5", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "1.8.5", - "shape": "direct" - }, - { - "checks": {}, - "expected": "informational: setup edits pyproject; poetry must resolve socket-patch[hook]", - "info": { - "lockChanged": true, - "poetryLockAfterSetup": { - "exit": 0, - "tail": "Resolving dependencies...\nCreating virtualenv poetry-patch-fixture in /matrix-final2/captures/1.8.5-direct-setup/project/.venv\n" - }, - "pyprojectChanged": true, - "pyprojectDiff": "[tool.poetry]\nname = \"poetry-patch-fixture\"\nversion = \"0.1.0\"\ndescription = \"\"\nauthors = [\"Socket \"]\n\n[tool.poetry.dependencies]\npython = \">=3.8\"\nurllib3 = \"1.26.18\"\nsocket-patch = { version = \"*\", extras = [\"hook\"] }\n", - "setupCheckExit": 0, - "setupEnvelope": { - "alreadyConfigured": 0, - "errors": 0, - "files": [ - { - "error": null, - "kind": "pth", - "path": "/matrix-final2/captures/1.8.5-direct-setup/project/pyproject.toml", - "status": "updated" - } - ], - "packageManager": "npm", - "pythonPackageManager": "poetry", - "status": "success", - "updated": 1 - }, - "setupExit": 0 - }, - "mode": "setup", - "passed": true, - "poetry": "1.8.5", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/1.8.5-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/1.8.5-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock --no-update -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.8.5-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/1.8.5-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "1.8.5", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.0.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.0.1-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.0.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.0.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.0.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.0.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "2.0.1", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/2.0.1-direct-agent-oot/venvs/poetry-patch-fixture-0k24feQr-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "2.0.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.0.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.0.1-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.0.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.0.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.0.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.0.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.0.1", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.0.1-pep621-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.0.1-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.0.1-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.0.1-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.0.1", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.1.4", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.1.4-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.1.4-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.1.4-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.1.4-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.1.4", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "2.1.4", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/2.1.4-direct-agent-oot/venvs/poetry-patch-fixture-V-8iOFCt-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "2.1.4", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.1.4", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.1.4-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.1.4-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.1.4-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.1.4-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.1.4", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.1.4", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.1.4-pep621-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.1.4-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.1.4-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.1.4-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.1.4", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.2.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.2.1-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.2.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.2.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.2.1-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.2.1", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "2.2.1", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/2.2.1-direct-agent-oot/venvs/poetry-patch-fixture-GNeKz0YO-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "2.2.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.2.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.2.1-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.2.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.2.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.2.1-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.2.1", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.2.1", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.2.1-pep621-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.2.1-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.2.1-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.2.1-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.2.1", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.3.4", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.3.4-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.3.4-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.3.4-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.3.4-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.3.4", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "2.3.4", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/2.3.4-direct-agent-oot/venvs/poetry-patch-fixture-a0nSdvf5-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "2.3.4", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.3.4", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.3.4-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.3.4-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.3.4-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.3.4-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.3.4", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.3.4", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.3.4-pep621-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.3.4-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.3.4-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.3.4-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.3.4", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.4.3", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "crlfPreserved": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.4.3-crlf-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.4.3-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.4.3-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "- Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.4.3-crlf-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.4.3", - "shape": "crlf" - }, - { - "checks": { - "appliedExactlyOne": true, - "installedBytesPatched": true, - "lockUnchanged": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "rollbackRestoresUpstreamBytes": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 1, - "status": "success", - "vendoredReverted": [] - }, - "rollbackRestoresUpstreamBytes": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - }, - "scanExit": 0, - "survivesRepeatInstall": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "warnings": [] - }, - "mode": "agent", - "passed": true, - "poetry": "2.4.3", - "shape": "direct" - }, - { - "checks": { - "bareScanSeesPoetryVenv": true, - "patchedViaPoetryRun": true, - "poetryRunScanApplied": true, - "rollbackClearsManifest": true, - "rollbackRestoresUpstream": true, - "survivesRepeatInstall": true, - "survivesSync": true - }, - "expected": "bareScanSeesPoetryVenv is informational (known crawler gap); the rest must pass", - "info": { - "applyPath": "bare", - "bareScan": { - "exit": 0, - "packageDirs": [], - "packagesWithPatches": 1, - "paths": [], - "scannedPackages": 2, - "urllib3Found": true - }, - "bareScanSeesPoetryVenv": { - "found": 1, - "scannedPackages": 2 - }, - "ootVenv": "/matrix-final2/captures/2.4.3-direct-agent-oot/venvs/poetry-patch-fixture-8DuawaLX-py3.12", - "patchedViaPoetryRun": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "poetryRunScanApplied": { - "applied": 1, - "exit": 0, - "path": "bare" - }, - "rollbackRestoresUpstream": { - "exit": 0, - "oracle": { - "urllib3/response.py": "ea86196bb5cb3f20fee709d7507cd6b9b2c98017050f3a70033c27f47051ce06" - } - }, - "survivesRepeatInstall": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "survivesSync": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - } - } - }, - "mode": "agent-oot", - "passed": true, - "poetry": "2.4.3", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.4.3", - "shape": "direct" - }, - { - "checks": {}, - "expected": "informational: setup edits pyproject; poetry must resolve socket-patch[hook]", - "info": { - "lockChanged": true, - "poetryLockAfterSetup": { - "exit": 0, - "tail": "Resolving dependencies...\nCreating virtualenv poetry-patch-fixture in /matrix-final2/captures/2.4.3-direct-setup/project/.venv\n" - }, - "pyprojectChanged": true, - "pyprojectDiff": "[tool.poetry]\nname = \"poetry-patch-fixture\"\nversion = \"0.1.0\"\ndescription = \"\"\nauthors = [\"Socket \"]\n\n[tool.poetry.dependencies]\npython = \">=3.8\"\nurllib3 = \"1.26.18\"\nsocket-patch = { version = \"*\", extras = [\"hook\"] }\n", - "setupCheckExit": 0, - "setupEnvelope": { - "alreadyConfigured": 0, - "errors": 0, - "files": [ - { - "error": null, - "kind": "pth", - "path": "/matrix-final2/captures/2.4.3-direct-setup/project/pyproject.toml", - "status": "updated" - } - ], - "packageManager": "npm", - "pythonPackageManager": "poetry", - "status": "success", - "updated": 1 - }, - "setupExit": 0 - }, - "mode": "setup", - "passed": true, - "poetry": "2.4.3", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.4.3-direct-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "dynamic].\nIf you want to set the version dynamically via `poetry build --local-version` or you are using a plugin, which sets the version dynamically, you should define the version in [tool.poetry] and add 'version' to [project.dynamic].\nWarning: [tool.poetry.description] is deprecated. Use [project.description] instead.\nWarning: [tool.poetry.authors] is deprecated. Use [project.authors] instead.\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.4.3-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.4.3-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.4.3-direct-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.4.3", - "shape": "direct" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasUrlSource": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackClearsRedirectLedger": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 1, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 1, - "failed": [], - "reverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Installing dependencies from lock file\n\nPackage operations: 0 installs, 1 update, 0 removals\n\n - Updating urllib3 (1.26.18 -> 1.26.18 https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [] - }, - "mode": "hosted", - "passed": true, - "poetry": "2.4.3", - "shape": "pep621" - }, - { - "checks": { - "appliedExactlyOne": true, - "freshCloneInstallsPatch": true, - "installedBytesPatched": true, - "lockHasFileSource": true, - "lockOnlyVendorApplies": true, - "lockRewritten": true, - "lockUnchangedByInstall": true, - "poetryInstallExit0": true, - "pyprojectUnchanged": true, - "recordHasFiles": true, - "rescanIdempotent": true, - "rollbackClearsManifest": true, - "rollbackExit0": true, - "rollbackKeepsPyproject": true, - "rollbackRemovesVendoredWheel": true, - "rollbackRestoresLockBytes": true, - "tamperBehaviorAsDocumented": true, - "vendoredWheelPresent": true, - "warmInstallReplacesUpstream": true - }, - "info": { - "applied": 1, - "appliedExactlyOne": { - "applied": 1, - "status": "success", - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "freshCloneInstallsPatch": { - "exit": 0, - "oracle": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "tail": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.4.3-pep621-vendored/fresh/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "installedBytesPatched": { - "urllib3/response.py": "9027726cab26bb63b978e6af295b22ec6172b100cda66d9b91cdc30bebc03730" - }, - "lockCheck": { - "cmd": "check --lock", - "exit": 0, - "tail": "All set!\n" - }, - "lockOnlyVendor": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "lockOnlyVendorApplies": { - "applied": 1, - "codes": [ - "vendor_fetched_missing", - "vendor_prebuilt_downloaded" - ], - "exit": 0 - }, - "poetryInstallExit0": "Installing dependencies from lock file\n\nPackage operations: 1 install, 0 updates, 0 removals\n\n - Installing urllib3 (1.26.18 /matrix-final2/captures/2.4.3-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n", - "relock": { - "cmd": "lock -n", - "exit": 0, - "lockBytesUnchanged": true, - "patchSourceKept": true, - "pyprojectUnchanged": true, - "tail": "Resolving dependencies...\n" - }, - "rescanIdempotent": { - "applied": 0, - "exit": 0, - "status": "success" - }, - "rollbackEnvelope": { - "failed": 0, - "hosted": { - "editedFiles": 0, - "failed": [], - "reverted": [], - "unsupported": [] - }, - "manifest": { - "preserved": false, - "removedEntries": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "rolledBack": 0, - "status": "success", - "vendoredReverted": [ - "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - ] - }, - "scanExit": 0, - "tamper": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "tamperBehaviorAsDocumented": { - "expectsReject": true, - "installExit": 1, - "installedPatchedAnyway": false - }, - "uuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "vex": { - "exit": 0, - "statements": 1 - }, - "warmInstall": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.4.3-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warmInstallReplacesUpstream": { - "exit": 0, - "patched": true, - "tail": "Updating urllib3 (1.26.18 -> 1.26.18 /matrix-final2/captures/2.4.3-pep621-vendored/project/.socket/vendor/pypi/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)\n" - }, - "warnings": [ - { - "action": "applied", - "files": [ - { - "path": "urllib3/response.py", - "verified": true - } - ], - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl" - }, - { - "action": "skipped", - "errorCode": "vendor_prebuilt_downloaded", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "reason": "vendored the wheel for pkg:pypi/urllib3@1.26.18 from the patch service (https://patch.socket.dev/patch/pypi/urllib3/1.26.18/7e52b8b6-53f2-4dc8-860a-1ae7ebd8be0e/e828efa5-5c6d-43f3-9909-03f5ac232b98/urllib3-1.26.18-py2.py3-none-any.whl)" - } - ] - }, - "mode": "vendored", - "passed": true, - "poetry": "2.4.3", - "shape": "pep621" - }, - { - "checks": {}, - "expected": "informational: setup edits pyproject; poetry must resolve socket-patch[hook]", - "info": { - "lockChanged": true, - "poetryLockAfterSetup": { - "exit": 0, - "tail": "Creating virtualenv poetry-patch-fixture in /matrix-final2-setup/captures/1.1.15-direct-setup/project/.venv\nResolving dependencies...\n" - }, - "pyprojectChanged": true, - "pyprojectDiff": "[tool.poetry]\nname = \"poetry-patch-fixture\"\nversion = \"0.1.0\"\ndescription = \"\"\nauthors = [\"Socket \"]\n\n[tool.poetry.dependencies]\npython = \">=3.8\"\nurllib3 = \"1.26.18\"\nsocket-patch = { version = \"*\", extras = [\"hook\"] }\n", - "setupCheckExit": 0, - "setupEnvelope": { - "alreadyConfigured": 0, - "errors": 0, - "files": [ - { - "error": null, - "kind": "pth", - "path": "/matrix-final2-setup/captures/1.1.15-direct-setup/project/pyproject.toml", - "status": "updated" - } - ], - "packageManager": "npm", - "pythonPackageManager": "poetry", - "status": "success", - "updated": 1 - }, - "setupExit": 0 - }, - "mode": "setup", - "passed": true, - "poetry": "1.1.15", - "shape": "direct" - } - ] -} \ No newline at end of file diff --git a/docs/testing/uv-compatibility.md b/docs/testing/uv-compatibility.md index 86b3f4e82..16f1a67ba 100644 --- a/docs/testing/uv-compatibility.md +++ b/docs/testing/uv-compatibility.md @@ -75,7 +75,7 @@ frozen, locked, and ordinary installation outcomes separately where supported. `pypi_uv_lock_package_missing`. - Native lock versions other than `version = 1`, and PEP 751 versions other than `lock-version = "1.0"`, are refused. Lock `revision` values 1 (0.6.0–0.6.14), - 2 (0.6.15–0.8.3) and 3 (0.8.4 onward) are all covered by the matrix below. + 2 (0.6.15–0.8.3) and 3 (0.8.4 onward) are covered by the release-family runner. - Command availability boundaries observed with real binaries: `uv lock` writes a lock from 0.1.45 (see above); `uv export` from 0.4.1, its `--output-file` flag from 0.4.7 (the harness reads the export from stdout @@ -250,9 +250,8 @@ untouched, and the installed bytes: A plain `uv sync` that rewrites the lock is recorded (`lockUnchanged: false`), not raised: it is a real observation, not a harness error. No export or PEP 751 lanes run for the variants. Each version row in `results.json` carries a -`variants` summary; the tables below are printed from that file with -`--render-doc-table` (see the markers in the results section), so the doc can be -regenerated after a full run without hand-editing: +`variants` summary. Render a summary alongside the run's output with +`--render-doc-table`: ```sh python3 scripts/backtest-uv.py --render-doc-table /tmp/socket-patch-uv-backtest/results.json @@ -299,210 +298,5 @@ Lanes a release lacks are reported `n/a`: uv 0.1.45 writes the locks need `uv lock --script` (0.5.17), pylock lanes need `uv pip sync pylock.toml` (0.7). -## Full matrix results - - -The complete run finished on **2026-09-15**, using -**macOS-26.6.2-arm64-arm-64bit-Mach-O** and Python **3.9.6**. It tested -socket-patch source commit `17d0dcb84bab1bec030117e0f111c7bfd893c2eb` -(`socket-patch 4.0.0`), with binary SHA-256: - -```text -be7a0e3dd86d540b0dc038437410bec6042bcaad5ae8beba92fae23015b56548 -``` - -**1403 installed-byte comparisons** ran, with **18 mismatches**. **1086 -lock-preservation checks** were recorded — every install attempt against a -patched lock (`--frozen` and `--locked` where the binary provides them, plain -`uv sync` where it does not, `uv run --frozen --script`, `uv pip sync -pylock.toml`, and the project-variant installs), including failed installs whose -lock was left untouched — and **32 changed the lock**. `--frozen` never writes -the lock, so the 383 `--locked` rows are the ones that measure preservation; 351 -of them exited 0. The [machine-readable results](uv-compatibility/results.json) -contain all 2769 observations and their command definitions. The [binary -catalog](uv-compatibility/binaries.json) records each uv wheel's public PyPI -source and verified hash. - -Each paired result below is **hosted / vendored**. “Pass” means the installed -`urllib3/response.py` matched the published patch; “—” means that uv binary did -not provide the format or command. Requirements include plain and hashed -compilation. PEP 751 covers both standalone locks and exported locks. - -| uv | Native grammar | Native H/V | Requirements H/V | Requirements export H/V | Scripts H/V | PEP 751 H/V | Verified installs | -|----|----------------|------------|------------------|-------------------------|-------------|-------------|-------------------| -| 0.0.5 | No native lock | — / — | Pass / rejected path | — / — | — / — | — / — | 2 | -| 0.1.0 | No native lock | — / — | Pass / rejected path | — / — | — / — | — / — | 2 | -| 0.1.23 | No native lock | — / — | Pass / rejected path | — / — | — / — | — / — | 2 | -| 0.1.24 | No native lock | — / — | Pass / Pass | — / — | — / — | — / — | 4 | -| 0.1.44 | No native lock | — / — | Pass / Pass | — / — | — / — | — / — | 4 | -| 0.1.45 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 6 | -| 0.2.0 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 6 | -| 0.2.5 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 6 | -| 0.2.6 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 6 | -| 0.2.17 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 6 | -| 0.2.18 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 6 | -| 0.2.34 | `distribution`, v1 | Pass / refused | Pass / Pass | — / — | — / — | — / — | 7 | -| 0.2.35 | `package`, v1 | Pass / Pass¹ | Pass / Pass | — / — | — / — | — / — | 24 | -| 0.2.36 | `package`, v1 | Pass / Pass¹ | Pass / Pass | — / — | — / — | — / — | 24 | -| 0.2.37 | `package`, v1 | Pass / Pass¹ | Pass / Pass | — / — | — / — | — / — | 28 | -| 0.3.0 | `package`, v1 | Pass / Pass¹ | Pass / Pass | — / — | — / — | — / — | 28 | -| 0.3.5 | `package`, v1 | Pass / Pass | Pass / Pass | — / — | — / — | — / — | 28 | -| 0.4.0 | `package`, v1 | Pass / Pass | Pass / Pass | — / — | — / — | — / — | 28 | -| 0.4.1 | `package`, v1 | Pass / Pass | Pass / Pass | Pass / Pass | — / — | — / — | 30 | -| 0.4.30 | `package`, v1 | Pass / Pass | Pass / Pass | Pass / Pass | — / — | — / — | 36 | -| 0.5.0 | `package`, v1 | Pass / Pass | Pass / Pass | Pass / Pass | — / — | — / — | 36 | -| 0.5.16 | `package`, v1 | Pass / Pass | Pass / Pass | Pass / Pass | — / — | — / — | 42 | -| 0.5.17 | `package`, v1 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | — / — | 48 | -| 0.5.31 | `package`, v1 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | — / — | 48 | -| 0.6.0 | `package`, v1 r1 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | — / — | 48 | -| 0.6.14 | `package`, v1 r1 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | — / — | 48 | -| 0.6.15 | `package`, v1 r2 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.6.17 | `package`, v1 r2 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.7.0 | `package`, v1 r2 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.7.22 | `package`, v1 r2 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.8.0 | `package`, v1 r2 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.8.3 | `package`, v1 r2 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.8.4 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.8.24 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.9.0 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.9.30 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.10.0 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.10.12 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.11.0 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.11.33 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.12.0 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | -| 0.12.15 | `package`, v1 r3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | 52 | - -### Project variants (uv ≥ 0.2.35) - -Each `[[package]]`-grammar binary also locks five further project shapes -(`variant-*` cases in the results), scans them in both modes, and installs from -the patched lock with `--frozen`, `--locked` (where available) and a plain `uv -sync`, each into a fresh environment. “Pass” requires the patched bytes from -every executed install and an untouched lock after `--locked`; “Fail: …” names -the installs that missed; “refused” means the CLI reported the shape unsupported -and left the lock unpatched; “—” means the binary cannot lock that shape (no -`[dependency-groups]`, no `[manifest]` constraints, or no `exclude-newer` -setting). - -| uv | tool-uv-dev H/V | dependency-groups H/V | extras-duplicate H/V | constraints H/V | transitive H/V | -|----|-----------------|-----------------------|----------------------|-----------------|----------------| -| 0.2.35 | Pass / Pass | — / — | Pass / Pass | — / — | Fail: locked, plain / Fail: locked, plain | -| 0.2.36 | Pass / Pass | — / — | Pass / Pass | — / — | Fail: locked, plain / Fail: locked, plain | -| 0.2.37 | Pass / Pass | — / — | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.3.0 | Pass / Pass | — / — | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.3.5 | Pass / Pass | — / — | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.4.0 | Pass / Pass | — / — | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.4.1 | Pass / Pass | — / — | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.4.30 | Pass / Pass | Pass / Pass | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.5.0 | Pass / Pass | Pass / Pass | Pass / Pass | Fail: locked / Fail: locked | Fail: locked, plain / Fail: locked, plain | -| 0.5.16 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.5.17 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.5.31 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.6.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.6.14 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.6.15 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.6.17 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.7.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.7.22 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.8.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.8.3 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.8.4 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.8.24 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.9.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.9.30 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.10.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.10.12 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.11.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.11.33 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.12.0 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | -| 0.12.15 | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | Pass / Pass | - - -Nonzero outcomes and mismatches in this run, and what each one is: - -- uv 0.0.5 through 0.1.23 rejected vendored requirements' local wheel path - syntax (`Unexpected '.', expected '-c', '-e', '-r' or the start of a - requirement`); 0.1.24 onward accepted it. Both hosted requirements variants - installed the patch on every binary. uv 0.0.5–0.1.44 have no working - `uv lock` (the `lock` rows exit 2), so their native lanes are `—`. -- Native vendoring on every `[[distribution]]`-grammar binary (0.1.45 through - 0.2.34) was refused with `pypi_uv_legacy_lock_unsupported`; hosted native - installs — in all three shapes: sub-table artifacts (through 0.2.5), inline - artifacts with string sources (0.2.6–0.2.17), and inline-table sources - (0.2.18–0.2.34) — and both requirements modes installed the patch. -- ¹ uv 0.2.35, 0.2.36, 0.2.37 and 0.3.0 cannot build the root fixture from an - empty cache under `--offline` (`setuptools>=40.8.0` was absent). The - network-enabled retry (`project-vendored-frozen-sync-root-build-networked`) - installed the patched wheel; the subsequent locked and ordinary installation - checks also passed. -- Export, script-lock, and PEP 751 commands unavailable in older binaries were - recorded as unavailable, not installation successes (`uv export` from 0.4.1, - `uv lock --script` from 0.5.17, PEP 751 compilation from 0.6.15 — 0.6.14 - exits 2 on the `pylock.toml` output). Some older uv binaries accepted an - output filename ending in `pylock.toml` but emitted requirements text; those - results have `formatSupported: false`. -- The **18 installed-byte mismatches** are all the `transitive` variant's plain - `uv sync` rows on 0.2.35–0.5.0 (nine binaries, both modes): those releases - do not apply `[tool.uv.sources]` to `override-dependencies`, so the plain - sync re-resolves the override against the registry and installs the pristine - wheel; `--frozen` installed the patch on every one of them. This is the - boundary the `pypi_uv_override_requires_uv_0_5_6` advisory names; from - 0.5.16 (the first ≥ 0.5.6 binary in the matrix) every install passes. -- The **32 lock changes** and the 32 non-zero `--locked` rows are those same - 18 transitive rows plus the `constraints` variant's plain-sync / `--locked` - rows on 0.2.37–0.5.0 (seven binaries, both modes): those releases serialize - `[manifest] constraints` as `{ name, specifier }` regardless of sources, so - they reject the repointed entry under `--locked` and rewrite it back on a - plain sync — which still installed the patch (no mismatch). 0.2.35 and - 0.2.36 do not record constraints in the lock (`—`). This is the boundary the - `pypi_uv_constraints_require_uv_0_5_6` advisory names; from 0.5.16 every - constraints install passes with the lock untouched. -- Every other `--locked`, `--frozen`, plain, script and PEP 751 install - delivered the patched bytes with the lock byte-unchanged, including the - `[tool.uv] dev-dependencies`, `[dependency-groups]` and extras-duplicate - shapes on every binary that can lock them. - -## Completed conditional-requirements and refusal checks - -The following checks ran on 2026-09-14 with uv `0.12.13`, Python `3.9.6`, the -rebuilt CLI, real PyPI distributions, and the public Socket patch service. -Their [sanitized command evidence](uv-compatibility/conditional-probes.json) -records both the installed hashes and the byte-preservation assertions. These -supplemental probes were captured during implementation; their individual CLI -binary hashes were not recorded, so they are kept separate from the exact-source -matrix above. - -| Case | Observed result | -|------|-----------------| -| `urllib3==1.26.18` for Python below 3.10; `urllib3==2.6.3` for Python 3.10 and newer | Only 1.26.18 received a patch. The complete 2.6.3 requirement and original hash continuations remained byte-identical. Fresh hash-verified installation succeeded. | -| The same markers selecting 1.26.18 and 2.0.0, both with published patches | Each version received its own artifact URL and hash. A repeated scan and fresh hash-verified installation succeeded; one override did not replace the other's version. | -| Hashed `urllib3[socks]==1.26.18` with a platform marker | Extras and the marker survived the rewrite; unrelated dependency hashes were preserved. Fresh hash-verified installation succeeded. | -| A PEP 723 script locking both 1.26.18 and 2.0.0 | Hosted and vendored scans reported the competing-version refusal. Both the script and its lock remained byte-identical. | -| A native project locking both 1.26.18 and 2.0.0 | Hosted scan reported the competing-version refusal. Both `pyproject.toml` and `uv.lock` remained byte-identical. | - -The requirements inputs were generated with real uv compilation, including: - -```sh -uv pip compile requirements.in \ - --universal --python-version 3.9 \ - --generate-hashes --no-strip-markers \ - --output-file requirements.txt -socket-patch scan --mode hosted --json --yes --no-telemetry -uv venv .venv-sync --python /path/to/python3.9 -uv pip sync --python .venv-sync/bin/python \ - --require-hashes requirements.txt -``` - -The extras case also used `--no-strip-extras`. For the selected 1.26.18 patch, -UUID `e828efa5-5c6d-43f3-9909-03f5ac232b98`, the freshly installed -`urllib3/response.py` matched the published patched wheel's SHA-256: - -```text -21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4 -``` - -This hash records the patch selected for that run. Production patch ordering -can change; a later run must compare against the artifact it actually selects. +Full run results belong with the source revision and toolchain versions in CI +artifacts or a local output directory. See the [testing guide](README.md#ci-and-results). diff --git a/docs/testing/uv-compatibility/binaries.json b/docs/testing/uv-compatibility/binaries.json deleted file mode 100644 index 58ebb0e7a..000000000 --- a/docs/testing/uv-compatibility/binaries.json +++ /dev/null @@ -1,296 +0,0 @@ -[ - { - "version": "0.0.5", - "url": "https://files.pythonhosted.org/packages/0c/49/fe6bd6b2ca5b661461d608218ca79a004ae0f51dd069e33b629714fb442b/uv-0.0.5-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl", - "sha256": "2fb16b693c8997100040291890522880dde83f9fda533845ec24352d8becded5", - "uploaded": "2024-02-15T18:56:14.105999Z", - "filename": "uv-0.0.5-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl" - }, - { - "version": "0.1.0", - "url": "https://files.pythonhosted.org/packages/0c/e3/415f40a86918316951b69b42661731bf6c5e5007f4063bc564773aec4815/uv-0.1.0-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl", - "sha256": "71291b3b3222da25a6af5ab9dfaec3bdd97fd4f0d21cf38a04cbd63000fa9da5", - "uploaded": "2024-02-15T19:44:47.783250Z", - "filename": "uv-0.1.0-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl" - }, - { - "version": "0.1.23", - "url": "https://files.pythonhosted.org/packages/e4/02/824e40366ecd913483d67723aa10079b5d127b43d7f8c3f164dcf19fb9c4/uv-0.1.23-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl", - "sha256": "d9d1d6d2bca50b9ea2ed764a6931b53995f6b5dbf3def9eafbcec57a88b4a6e2", - "uploaded": "2024-03-21T03:09:59.075241Z", - "filename": "uv-0.1.23-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl" - }, - { - "version": "0.1.24", - "url": "https://files.pythonhosted.org/packages/1e/ef/90fc17103183c23e8e5142c455b1ca8c1c38142c89c8aaa27f7ab37c34f5/uv-0.1.24-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl", - "sha256": "33d74c4c67df34de18c4318a6c568efef9dfab6d05332b1d1eddc8e516fc8806", - "uploaded": "2024-03-22T20:15:08.127518Z", - "filename": "uv-0.1.24-py3-none-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl" - }, - { - "version": "0.1.44", - "url": "https://files.pythonhosted.org/packages/85/6a/4e98521c359f593cdd8cebc6381c09be1d133bd93031e76accc6b8aa7788/uv-0.1.44-py3-none-macosx_11_0_arm64.whl", - "sha256": "e247dca0d8d42d71032ac99ef3d72a4fcbad4ae3114ef5979878a81a40fed274", - "uploaded": "2024-05-14T14:28:43.548037Z", - "filename": "uv-0.1.44-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.1.45", - "url": "https://files.pythonhosted.org/packages/7f/15/46efcaa86ebef51b8663d8beb95c8376fbdaaf45aeffbc269bf0a3527092/uv-0.1.45-py3-none-macosx_11_0_arm64.whl", - "sha256": "4e5d55f0f8b6ae416c72d78106e224c8e8338356da21ddebecc7b1723de80924", - "uploaded": "2024-05-20T21:05:54.623510Z", - "filename": "uv-0.1.45-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.0", - "url": "https://files.pythonhosted.org/packages/cc/4a/7c3d702c5920487d481bd03a3ca821f8886ad2d6937e49f4efc0a16c6e61/uv-0.2.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "ba5e339a0fb32a02142346eea4d46f6ad618a390df5d70515ba0e1d3c6f7ce41", - "uploaded": "2024-05-22T19:11:42.407716Z", - "filename": "uv-0.2.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.5", - "url": "https://files.pythonhosted.org/packages/06/d2/ef1c65a0715731da623b430757a9b851167309fc7e326140d27d246e6541/uv-0.2.5-py3-none-macosx_11_0_arm64.whl", - "sha256": "650f81439c4f65e86fdba84f2cbb6700a074b95d70c5cc3d38e8ce2b87e43a45", - "uploaded": "2024-05-28T18:33:49.720762Z", - "filename": "uv-0.2.5-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.6", - "url": "https://files.pythonhosted.org/packages/a0/53/4c9a7370ec5bf75b89b82117fae68d7bb268d229deb82c51264ca27a1368/uv-0.2.6-py3-none-macosx_11_0_arm64.whl", - "sha256": "1ac3b96c6284ef2e5367e62f31472cc3f27ba4c7e14f579e7c6dbd081943e38b", - "uploaded": "2024-06-03T18:22:26.325121Z", - "filename": "uv-0.2.6-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.17", - "url": "https://files.pythonhosted.org/packages/90/c0/27b6fc7cc85984b0c86ffd0e42abf4c97aeff2cc3425b09ce86e679bedae/uv-0.2.17-py3-none-macosx_11_0_arm64.whl", - "sha256": "d6628bcb0d21f2f8489ed33818fa6c2da3a472adead076864701ae7a3bafb4de", - "uploaded": "2024-06-26T23:39:17.070293Z", - "filename": "uv-0.2.17-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.18", - "url": "https://files.pythonhosted.org/packages/60/0d/d462d188343464876ca196f064ba1682982446012c4893da0d7dbba01a8c/uv-0.2.18-py3-none-macosx_11_0_arm64.whl", - "sha256": "eee9773a0a9f02d084a584279891df1fdf4de32d067f273b9480f86c9f91dcdb", - "uploaded": "2024-06-29T18:49:23.499620Z", - "filename": "uv-0.2.18-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.34", - "url": "https://files.pythonhosted.org/packages/f2/a0/840b0fa6b9f884384b558b8690cad603bdc0da2b7a67cec2755b612839c9/uv-0.2.34-py3-none-macosx_11_0_arm64.whl", - "sha256": "4ce15beeba44e4ea052d83c89eb4ea3586dfd68bab039c5cdf44b90fbfc5698d", - "uploaded": "2024-08-07T20:59:42.011904Z", - "filename": "uv-0.2.34-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.35", - "url": "https://files.pythonhosted.org/packages/00/eb/c578ebb0f606be6a3a1c37e36a8b6068008ceab54db95a2ab70452c792fd/uv-0.2.35-py3-none-macosx_11_0_arm64.whl", - "sha256": "3ff91eb85e0804d5f609f18a911b33d81b06e11c1bced1bf1396a2d738e97bc0", - "uploaded": "2024-08-10T00:42:30.944714Z", - "filename": "uv-0.2.35-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.36", - "url": "https://files.pythonhosted.org/packages/80/40/e951bc5598dbd7d58a6daf33a93977ecbaad60fdaa584610349f00acf521/uv-0.2.36-py3-none-macosx_11_0_arm64.whl", - "sha256": "8820dd5b77ffcda07dde09712a43d969d39b0aace112d8074c540f19a4911cc2", - "uploaded": "2024-08-13T17:28:27.711187Z", - "filename": "uv-0.2.36-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.2.37", - "url": "https://files.pythonhosted.org/packages/e6/84/2c973ddb320642d02d2d117123a61ec6666bbc0143f5263b1e0c791c1252/uv-0.2.37-py3-none-macosx_11_0_arm64.whl", - "sha256": "99d4f0f510c5aa807ef1141fd8cb31f25fb53587dadacb0e28e4f51eaca6f0ad", - "uploaded": "2024-08-16T02:45:56.044623Z", - "filename": "uv-0.2.37-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.3.0", - "url": "https://files.pythonhosted.org/packages/61/95/b6603342b9a0a180776e7aec845079cdc66fb521157ed9bf62b4e4174983/uv-0.3.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "39a4276afe0808ca6c033e0cd6cb73249f934b4a0c9d7b18a944f3f8ea635e27", - "uploaded": "2024-08-20T17:52:38.258401Z", - "filename": "uv-0.3.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.3.5", - "url": "https://files.pythonhosted.org/packages/83/8e/956ad3788cfa863cc8de148907e371b025acd97f7a0bb2a9e78ce63c2b1e/uv-0.3.5-py3-none-macosx_11_0_arm64.whl", - "sha256": "89c1515200a838014b1fa6c9cfb2b9a055bcad3178ccf7d31768bf38b43cac65", - "uploaded": "2024-08-27T17:10:36.293543Z", - "filename": "uv-0.3.5-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.4.0", - "url": "https://files.pythonhosted.org/packages/2e/86/9844e8ab08e25cbf2094e2fa1a7ad66563036bfed77b46986b6a2489c10c/uv-0.4.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "02e0295566454289348de502677e2240ad86f2cb5fa058504e1b2ca2a2ebf7e1", - "uploaded": "2024-08-28T18:00:42.051786Z", - "filename": "uv-0.4.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.4.1", - "url": "https://files.pythonhosted.org/packages/46/ad/90e0d7a448b4c92846589c8bb92813ac45d2b123a2b9d4cab4167e805f9f/uv-0.4.1-py3-none-macosx_11_0_arm64.whl", - "sha256": "fcdc6503100e86fecf6a727d3149e54581e8e9ad6c10e814fc5d22c1e80fab8d", - "uploaded": "2024-08-30T14:42:40.152858Z", - "filename": "uv-0.4.1-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.4.30", - "url": "https://files.pythonhosted.org/packages/67/37/8994c3d0be99851a21a6ee01bbf3cb35ddc4b202a2f6f4014098d5893660/uv-0.4.30-py3-none-macosx_11_0_arm64.whl", - "sha256": "353617bfcf72e1eabade426d83fb86a69d11273d1612aabc3f4566d41c596c97", - "uploaded": "2024-11-05T01:13:59.667063Z", - "filename": "uv-0.4.30-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.5.0", - "url": "https://files.pythonhosted.org/packages/69/fb/e778bce57b12eac37c1e9e8e1efc8b190a2c72dee02b532d13706be447f4/uv-0.5.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "a3bc6911be7d86f3750bce1580e664877a3a88c126eb68afbb132cd0896fd109", - "uploaded": "2024-11-07T23:05:15.972013Z", - "filename": "uv-0.5.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.5.16", - "url": "https://files.pythonhosted.org/packages/0f/c4/74f4507f48ce5e38cef46cecd7716af0348dffcb3d40245189422226c7b7/uv-0.5.16-py3-none-macosx_11_0_arm64.whl", - "sha256": "3419888b178b82511faebd8d1ca9cb9f5920a7142406898d76878adaffe8dfb1", - "uploaded": "2025-01-08T16:40:50.904248Z", - "filename": "uv-0.5.16-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.5.17", - "url": "https://files.pythonhosted.org/packages/f1/7e/4c8b7ca07945fe6ffd1a7e5d1f992b72534be69e97e20a2536d192734adc/uv-0.5.17-py3-none-macosx_11_0_arm64.whl", - "sha256": "12789bf19457e3c5fc20767960203ab60222124afe2cbdfde92a657318651a64", - "uploaded": "2025-01-10T21:13:54.034599Z", - "filename": "uv-0.5.17-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.5.31", - "url": "https://files.pythonhosted.org/packages/1f/5a/1eb42f481a9f9010c8c194d70ab375a6eda96d67ca1fd011bf869d4016c8/uv-0.5.31-py3-none-macosx_11_0_arm64.whl", - "sha256": "335c16f91b46b4f4a3b31c18cf112a0643d59d4c1708a177103621da0addbaef", - "uploaded": "2025-02-12T21:28:12.802785Z", - "filename": "uv-0.5.31-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.6.0", - "url": "https://files.pythonhosted.org/packages/6d/c3/c1e81bfdd3414492650ca2647dbb466bb9e0063ee71020dc49f5f011f9ac/uv-0.6.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "26d655adf59ec088f07a2459de3f5e0565e8f84f389bfe936a354e5e169dfc8f", - "uploaded": "2025-02-14T18:20:31.778738Z", - "filename": "uv-0.6.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.6.14", - "url": "https://files.pythonhosted.org/packages/72/89/e7fc8a047f08234cc26d1e37e5f573887744205d087f8e8e6f3d0feb04ce/uv-0.6.14-py3-none-macosx_11_0_arm64.whl", - "sha256": "9fc8fe58871b4fe02a863b05b8b1b25ef1b6c60d4d224e85338f5c2be0ab4f0e", - "uploaded": "2025-04-09T21:56:12.061201Z", - "filename": "uv-0.6.14-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.6.15", - "url": "https://files.pythonhosted.org/packages/f6/88/ad35ecc3b986274ff560267cb6e3b9119ca0f8cc82c61e2acae28c8b9ffe/uv-0.6.15-py3-none-macosx_11_0_arm64.whl", - "sha256": "f113d1746ce7fdffada6f9e12b2f667d2b9069a3c3d5b05b680836102f2586c1", - "uploaded": "2025-04-22T00:50:26.375142Z", - "filename": "uv-0.6.15-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.6.17", - "url": "https://files.pythonhosted.org/packages/a5/4f/66c7153120c155446f319647c1bafec2d9288f2b48d769cd9f9da39aa1f2/uv-0.6.17-py3-none-macosx_11_0_arm64.whl", - "sha256": "ce243bec19c47cc274e7e9eedbaeeb3dacbe94430b0f085dd506ba15a41676ee", - "uploaded": "2025-04-25T18:51:15.410083Z", - "filename": "uv-0.6.17-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.7.0", - "url": "https://files.pythonhosted.org/packages/ed/1d/cad304d6107208fdd90adf5ca519e86a2e35786cb7229d6cd39cf29bec3d/uv-0.7.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "1f48eeaeb46a5f81be873c1662c999e78ff267798ecea9dd48c7082e022048ec", - "uploaded": "2025-04-29T22:03:35.477030Z", - "filename": "uv-0.7.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.7.22", - "url": "https://files.pythonhosted.org/packages/64/f5/0ee734f5e988fd8f26aad1f150703fe8c7d664029c9c677b989b69caf104/uv-0.7.22-py3-none-macosx_11_0_arm64.whl", - "sha256": "573edda226dc26e6fea03aa89a45af2f2a367ad1f466af15c4eb54286dae042f", - "uploaded": "2025-07-17T17:00:10.010548Z", - "filename": "uv-0.7.22-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.8.0", - "url": "https://files.pythonhosted.org/packages/9d/98/9a89983caa05cf998eea3dac1e6cff2e0ab8099be0695fd8b9dc6a5038a0/uv-0.8.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "2d0ebf05eaee75921b3f23e7401a56bc0732bcdabb7469081ab00769340a93b4", - "uploaded": "2025-07-17T22:51:04.941749Z", - "filename": "uv-0.8.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.8.3", - "url": "https://files.pythonhosted.org/packages/9c/ba/8ceec5d6a1adf6b827db557077d8059e573a84c3708a70433d22a0470fab/uv-0.8.3-py3-none-macosx_11_0_arm64.whl", - "sha256": "3f904f574dc2d7aa1d96ddf2483480ecd121dc9d060108cadd8bff100b754b64", - "uploaded": "2025-07-24T21:13:57.570096Z", - "filename": "uv-0.8.3-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.8.4", - "url": "https://files.pythonhosted.org/packages/16/39/7d4b68132868c550ae97c3b2c348c55db47a987dff05ab0e5f577bf0e197/uv-0.8.4-py3-none-macosx_11_0_arm64.whl", - "sha256": "edc813645348665a3b4716a7d5e961cf7c8d1d3bfb9d907a4f18cf87c712a430", - "uploaded": "2025-07-30T17:10:20.417141Z", - "filename": "uv-0.8.4-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.8.24", - "url": "https://files.pythonhosted.org/packages/ea/00/08f4e93989129bb3378f20315dddcac6f8cf26a12bdd90443a340e7ecdb4/uv-0.8.24-py3-none-macosx_11_0_arm64.whl", - "sha256": "a2bd708a545c1c21d7be8575f4cff00d0cff26be13fc81e3f7e54b8751fb90c0", - "uploaded": "2025-10-07T03:33:24.533046Z", - "filename": "uv-0.8.24-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.9.0", - "url": "https://files.pythonhosted.org/packages/8e/06/f5e38314e318bfaa20ccce966f6d0a69b093854648d31085b2d8b2097aab/uv-0.9.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "b900e84d992a657e16371426dbb030ab031c0322a604b632dada34401ebe7145", - "uploaded": "2025-10-07T23:44:30.076333Z", - "filename": "uv-0.9.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.9.30", - "url": "https://files.pythonhosted.org/packages/42/5f/3ccc9415ef62969ed01829572338ea7bdf4c5cf1ffb9edc1f8cb91b571f3/uv-0.9.30-py3-none-macosx_11_0_arm64.whl", - "sha256": "777ecd117cf1d8d6bb07de8c9b7f6c5f3e802415b926cf059d3423699732eb8c", - "uploaded": "2026-02-04T21:45:40.881824Z", - "filename": "uv-0.9.30-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.10.0", - "url": "https://files.pythonhosted.org/packages/ee/77/ec8f24f8d0f19c4fda0718d917bb78b9e6f02a4e1963b401f1c4f4614a54/uv-0.10.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "aefea608971f4f23ac3dac2006afb8eb2b2c1a2514f5fee1fac18e6c45fd70c4", - "uploaded": "2026-02-05T20:57:10.581974Z", - "filename": "uv-0.10.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.10.12", - "url": "https://files.pythonhosted.org/packages/ce/db/c41ace81b8ef5d5952433df38e321c0b6e5f88ce210c508b14f84817963f/uv-0.10.12-py3-none-macosx_11_0_arm64.whl", - "sha256": "551f799d53e397843b6cde7e3c61de716fb487da512a21a954b7d0cbc06967e0", - "uploaded": "2026-03-19T21:50:53.693778Z", - "filename": "uv-0.10.12-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.11.0", - "url": "https://files.pythonhosted.org/packages/d9/1c/6ddd0febcea06cf23e59d9bff90d07025ecfd600238807f41ed2bdafd159/uv-0.11.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "4b0ebbd7ae019ea9fc4bff6a07d0c1e1d6784d1842bbdcb941982d30e2391972", - "uploaded": "2026-03-23T22:05:48.771767Z", - "filename": "uv-0.11.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.11.33", - "url": "https://files.pythonhosted.org/packages/4d/e5/17a4e36299e9bd5e8101680be697c7832afac686d1fe8b28be28046c1d95/uv-0.11.33-py3-none-macosx_11_0_arm64.whl", - "sha256": "8017991a398a55d177c33ecdb29beb33e7b53969921183e4681e3e5b278d73c2", - "uploaded": "2026-07-28T10:24:17.589531Z", - "filename": "uv-0.11.33-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.12.0", - "url": "https://files.pythonhosted.org/packages/a5/7b/15d6865264120bd30c738b4bf63ddff66d087087cadeb2a6b88c6284a446/uv-0.12.0-py3-none-macosx_11_0_arm64.whl", - "sha256": "009758d8fde2da2b90900f5fe863c71d0e1b8b28bbdba59863ceb967973a3735", - "uploaded": "2026-07-28T18:56:32.904863Z", - "filename": "uv-0.12.0-py3-none-macosx_11_0_arm64.whl" - }, - { - "version": "0.12.15", - "url": "https://files.pythonhosted.org/packages/84/62/82e86e03e111463ab224c132c0f0e6b649d98d22710b177fbc000d379103/uv-0.12.15-py3-none-macosx_11_0_arm64.whl", - "sha256": "03b2c763f8b3c5595fa103221bc667e3af0146f8cb327aa06630ebcf5cfe16e9", - "uploaded": "2026-09-15T12:07:07.611580Z", - "filename": "uv-0.12.15-py3-none-macosx_11_0_arm64.whl" - } -] diff --git a/docs/testing/uv-compatibility/conditional-probes.json b/docs/testing/uv-compatibility/conditional-probes.json deleted file mode 100644 index 8cdb6af55..000000000 --- a/docs/testing/uv-compatibility/conditional-probes.json +++ /dev/null @@ -1,573 +0,0 @@ -{ - "date": "2026-09-14", - "uvVersion": "0.12.13", - "pythonVersion": "3.9.6", - "provenance": "Supplemental real-service probes captured during implementation; an exact CLI binary hash was not recorded for these individual probes. The separately recorded release-family matrix identifies its tested source and binary.", - "redactions": [ - "Working directories and executable paths use placeholders.", - "Hosted artifact URLs are redacted to remove download grants.", - "CLI output keeps command results and refusal details; patch catalog descriptions are omitted." - ], - "cases": [ - { - "case": "conditional-unpatched-version", - "otherVersionRequirementByteIdentical": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "expectedPatchedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "commands": [ - { - "command": [ - "", - "venv", - ".venv", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nActivate with: source .venv/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "install", - "--python", - "/.venv/bin/python", - "" - ], - "cwd": "", - "key": "install-original", - "exitCode": 0, - "stderr": "Resolved 1 package in 0.82ms\nPrepared 1 package in 5ms\nInstalled 1 package in 1ms\n + urllib3==1.26.18 (from file://)\n" - }, - { - "command": [ - "", - "scan", - "--cwd", - "", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "", - "key": "scan-single-published-version", - "exitCode": 0, - "cliResult": { - "status": "success", - "scannedPackages": 2, - "lockfileOnlyPackages": 1, - "redirect": { - "mode": "hosted", - "redirected": 1, - "rewrittenFiles": [ - "requirements.txt" - ], - "skipped": [], - "warnings": [], - "dryRun": false - } - }, - "stderr": "No SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNon-interactive mode: auto-selecting first option.\n" - }, - { - "command": [ - "", - "venv", - ".venv-sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "fresh-venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv-sync\nActivate with: source .venv-sync/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "sync", - "--python", - "/.venv-sync/bin/python", - "--require-hashes", - "requirements.txt" - ], - "cwd": "", - "key": "hash-verified-sync", - "exitCode": 0, - "stderr": "Using Python 3.9.6 environment at: .venv-sync\nResolved 1 package in 551ms\nPrepared 1 package in 157ms\nInstalled 1 package in 5ms\n + urllib3==1.26.18 (from https://patch.socket.dev/\n" - } - ] - }, - { - "case": "conditional-two-patched-versions", - "bothPublishedVersionsRetainOwnArtifact": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "expectedPatchedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "commands": [ - { - "command": [ - "", - "venv", - ".venv", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nActivate with: source .venv/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "install", - "--python", - "/.venv/bin/python", - "" - ], - "cwd": "", - "key": "install-original", - "exitCode": 0, - "stderr": "Resolved 1 package in 1ms\nPrepared 1 package in 6ms\nInstalled 1 package in 1ms\n + urllib3==1.26.18 (from file://)\n" - }, - { - "command": [ - "", - "scan", - "--cwd", - "", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "", - "key": "scan-two-published-versions-rerun", - "exitCode": 0, - "cliResult": { - "status": "success", - "scannedPackages": 1, - "lockfileOnlyPackages": 0, - "redirect": { - "mode": "hosted", - "redirected": 1, - "rewrittenFiles": [], - "skipped": [], - "warnings": [], - "dryRun": false - } - }, - "stderr": "No SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNon-interactive mode: auto-selecting first option.\n" - }, - { - "command": [ - "", - "venv", - ".venv-sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "fresh-venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv-sync\nActivate with: source .venv-sync/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "sync", - "--python", - "/.venv-sync/bin/python", - "--require-hashes", - "requirements.txt" - ], - "cwd": "", - "key": "hash-verified-sync", - "exitCode": 0, - "stderr": "Using Python 3.9.6 environment at: .venv-sync\nResolved 1 package in 1.75s\nPrepared 1 package in 218ms\nInstalled 1 package in 4ms\n + urllib3==1.26.18 (from https://patch.socket.dev/\n" - } - ] - }, - { - "case": "extras-and-marker", - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "expectedPatchedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "commands": [ - { - "command": [ - "", - "pip", - "compile", - "requirements.in", - "--generate-hashes", - "--universal", - "--no-strip-extras", - "--no-strip-markers", - "-o", - "requirements.txt" - ], - "cwd": "", - "key": "compile", - "exitCode": 0, - "stdout": "# This file was autogenerated by uv via the following command:\n# uv pip compile requirements.in --generate-hashes --universal --no-strip-extras --no-strip-markers -o requirements.txt\npysocks==1.7.1 ; sys_platform == 'darwin' \\\n --hash=sha256:08e69f092cc6dbe92a0fdd16eeb9b9ffbc13cadfe5ca4c7bd92ffb078b293299 \\\n --hash=sha256:2725bd0a9925919b9b51739eea5f9e2bae91e83288108a9ad338b2e3a4435ee5 \\\n --hash=sha256:3f8804571ebe159c380ac6de37643bb4685970655d3bba243530d6558b799aa0\n # via urllib3\nurllib3[socks]==1.26.18 ; sys_platform == 'darwin' \\\n --hash=sha256:34b97092d7e0a3a8cf7cd10e386f401b3737364026c45e622aa02903dffe0f07 \\\n --hash=sha256:f8ecc1bba5667413457c529ab955bf8c67b45db799d159066261719e328580a0\n # via -r requirements.in\n", - "stderr": "Resolved 2 packages in 261ms\n" - }, - { - "command": [ - "", - "venv", - ".venv", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nActivate with: source .venv/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "install", - "--python", - "/.venv/bin/python", - "" - ], - "cwd": "", - "key": "install-original", - "exitCode": 0, - "stderr": "Resolved 1 package in 0.84ms\nPrepared 1 package in 6ms\nInstalled 1 package in 1ms\n + urllib3==1.26.18 (from file://)\n" - }, - { - "command": [ - "", - "scan", - "--cwd", - "", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "", - "key": "socket-patch", - "exitCode": 0, - "cliResult": { - "status": "success", - "scannedPackages": 2, - "lockfileOnlyPackages": 1, - "redirect": { - "mode": "hosted", - "redirected": 1, - "rewrittenFiles": [ - "requirements.txt" - ], - "skipped": [], - "warnings": [], - "dryRun": false - } - }, - "stderr": "No SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNon-interactive mode: auto-selecting first option.\n" - }, - { - "command": [ - "", - "venv", - ".venv-sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "fresh-venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv-sync\nActivate with: source .venv-sync/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "sync", - "--python", - "/.venv-sync/bin/python", - "--require-hashes", - "requirements.txt" - ], - "cwd": "", - "key": "hashed-sync", - "exitCode": 0, - "stderr": "Using Python 3.9.6 environment at: .venv-sync\nResolved 2 packages in 424ms\nPrepared 2 packages in 142ms\nInstalled 2 packages in 4ms\n + pysocks==1.7.1\n + urllib3==1.26.18 (from https://patch.socket.dev/\n" - } - ] - }, - { - "case": "script-hosted-refusal", - "kind": "script", - "mode": "hosted", - "filesByteIdentical": { - "job.py": true, - "job.py.lock": true - }, - "commands": [ - { - "command": [ - "", - "venv", - ".venv", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nActivate with: source .venv/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "install", - "--python", - "/.venv/bin/python", - "" - ], - "cwd": "", - "key": "install-original", - "exitCode": 0, - "stderr": "Resolved 1 package in 1ms\nPrepared 1 package in 7ms\nInstalled 1 package in 1ms\n + urllib3==1.26.18 (from file://)\n" - }, - { - "command": [ - "", - "scan", - "--cwd", - "", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "", - "key": "scan", - "exitCode": 0, - "cliResult": { - "status": "success", - "scannedPackages": 2, - "lockfileOnlyPackages": 1, - "redirect": { - "mode": "hosted", - "redirected": 0, - "rewrittenFiles": [], - "skipped": [], - "warnings": [ - { - "code": "redirect_uv_lock_unsupported", - "detail": "job.py.lock: urllib3 resolves to multiple versions; a global uv source would replace other versions, so marker-specific source mappings are required" - }, - { - "code": "redirect_uv_lock_unsupported", - "detail": "job.py.lock: urllib3 resolves to multiple versions; a global uv source would replace other versions, so marker-specific source mappings are required" - } - ], - "dryRun": false - } - }, - "stderr": "No SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNon-interactive mode: auto-selecting first option.\nNon-interactive mode: auto-selecting first option.\n" - } - ] - }, - { - "case": "script-vendored-refusal", - "kind": "script", - "mode": "vendored", - "filesByteIdentical": { - "job.py": true, - "job.py.lock": true - }, - "commands": [ - { - "command": [ - "", - "venv", - ".venv", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nActivate with: source .venv/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "install", - "--python", - "/.venv/bin/python", - "" - ], - "cwd": "", - "key": "install-original", - "exitCode": 0, - "stderr": "Resolved 1 package in 1ms\nPrepared 1 package in 13ms\nInstalled 1 package in 1ms\n + urllib3==1.26.18 (from file://)\n" - }, - { - "command": [ - "", - "scan", - "--cwd", - "", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "", - "key": "scan", - "exitCode": 1, - "cliResult": { - "status": "partial_failure", - "scannedPackages": 2, - "lockfileOnlyPackages": 1, - "vendor": { - "status": "partialFailure", - "events": [ - { - "action": "skipped", - "purl": "pkg:pypi/urllib3@2.0.0?artifact_id=py3-none-any-whl", - "reason": "pkg:pypi/urllib3@2.0.0?artifact_id=py3-none-any-whl is not installed; fetched the pristine artifact from https://files.pythonhosted.org/packages/ca/25/fe81738a115a2f1005b19bd69b6253b7b5cd6c9119164f13f02ec627fc41/urllib3-2.0.0-py3-none-any.whl (integrity verified) and vendored from that copy \u2014 the project tree was not touched", - "errorCode": "vendor_fetched_missing" - }, - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_lock_unsupported", - "error": "job.py.lock: urllib3 resolves to multiple versions; a global uv source would replace other versions, so marker-specific source mappings are required" - }, - { - "action": "failed", - "purl": "pkg:pypi/urllib3@2.0.0?artifact_id=py3-none-any-whl", - "errorCode": "pypi_lock_unsupported", - "error": "job.py.lock: urllib3 resolves to multiple versions; a global uv source would replace other versions, so marker-specific source mappings are required" - } - ], - "summary": { - "discovered": 0, - "downloaded": 0, - "applied": 0, - "updated": 0, - "skipped": 0, - "failed": 2, - "removed": 0, - "verified": 0 - } - } - }, - "stderr": "No SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNon-interactive mode: auto-selecting first option.\nNon-interactive mode: auto-selecting first option.\nNo SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNo SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNo SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\n" - } - ] - }, - { - "case": "project-hosted-refusal", - "kind": "project", - "mode": "hosted", - "filesByteIdentical": { - "pyproject.toml": true, - "uv.lock": true - }, - "commands": [ - { - "command": [ - "", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "original-lock", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nResolved 3 packages in 251ms\nwarning: `urllib3==2.0.0` is yanked (reason: \"Truncated response bodies when streaming a large compressed body. Upgrade to at least 2.0.2 (See: https://github.com/urllib3/urllib3/issues/3009)\")\n" - }, - { - "command": [ - "", - "venv", - ".venv", - "--python", - "/usr/bin/python3" - ], - "cwd": "", - "key": "venv", - "exitCode": 0, - "stderr": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nActivate with: source .venv/bin/activate\n" - }, - { - "command": [ - "", - "pip", - "install", - "--python", - "/.venv/bin/python", - "" - ], - "cwd": "", - "key": "install-original", - "exitCode": 0, - "stderr": "Resolved 1 package in 0.79ms\nPrepared 1 package in 6ms\nInstalled 1 package in 1ms\n + urllib3==1.26.18 (from file://)\n" - }, - { - "command": [ - "", - "scan", - "--cwd", - "", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "", - "key": "scan", - "exitCode": 0, - "cliResult": { - "status": "success", - "scannedPackages": 2, - "lockfileOnlyPackages": 1, - "redirect": { - "mode": "hosted", - "redirected": 0, - "rewrittenFiles": [], - "skipped": [], - "warnings": [ - { - "code": "redirect_uv_project_unsupported", - "detail": "pyproject.toml: urllib3 resolves to multiple versions; a global uv source would replace other versions, so marker-specific source mappings are required" - }, - { - "code": "redirect_uv_project_unsupported", - "detail": "pyproject.toml: urllib3 resolves to multiple versions; a global uv source would replace other versions, so marker-specific source mappings are required" - } - ], - "dryRun": false - } - }, - "stderr": "No SOCKET_API_TOKEN set (and no socket-cli login found) \u2014 using the public patch API proxy (free patches only). Run `socket login` or set SOCKET_API_TOKEN to access org patches.\nNon-interactive mode: auto-selecting first option.\nNon-interactive mode: auto-selecting first option.\n" - } - ] - } - ] -} diff --git a/docs/testing/uv-compatibility/results.json b/docs/testing/uv-compatibility/results.json deleted file mode 100644 index d3721766c..000000000 --- a/docs/testing/uv-compatibility/results.json +++ /dev/null @@ -1,21810 +0,0 @@ -{ - "date": "2026-09-15", - "scope": "42 pinned uv releases on macOS-26.6.2-arm64-arm-64bit-Mach-O; interpreter /usr/bin/python3", - "pythonVersion": "3.9.6", - "socketPatchRevision": "17d0dcb84bab1bec030117e0f111c7bfd893c2eb", - "socketPatchVersion": "socket-patch 4.0.0", - "socketPatchBinarySha256": "be7a0e3dd86d540b0dc038437410bec6042bcaad5ae8beba92fae23015b56548", - "patchUuid": "e828efa5-5c6d-43f3-9909-03f5ac232b98", - "originalWheelSha256": "34b97092d7e0a3a8cf7cd10e386f401b3737364026c45e622aa02903dffe0f07", - "patchedWheelSha256": "ccc9a9e0b18a5efc7038c504cfc580e47d2e02e5390f2e29cad833cbccb956b6", - "patchedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "commands": { - "lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//original" - }, - "requirements-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//requirements-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//requirements-hosted" - }, - "requirements-hosted-pip-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "requirements.txt" - ], - "cwd": "/matrix//requirements-hosted" - }, - "requirements-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//requirements-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//requirements-vendored" - }, - "requirements-vendored-pip-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "requirements.txt" - ], - "cwd": "/matrix//requirements-vendored" - }, - "compile-plain": { - "args": [ - "/bin//uv", - "pip", - "compile", - "requirements.in", - "-o", - "requirements.txt" - ], - "cwd": "/matrix//requirements-plain-hosted" - }, - "requirements-plain-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//requirements-plain-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//requirements-plain-hosted" - }, - "requirements-plain-hosted-pip-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "requirements.txt" - ], - "cwd": "/matrix//requirements-plain-hosted" - }, - "compile-plain-variant-2": { - "args": [ - "/bin//uv", - "pip", - "compile", - "requirements.in", - "-o", - "requirements.txt" - ], - "cwd": "/matrix//requirements-plain-vendored" - }, - "requirements-plain-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//requirements-plain-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//requirements-plain-vendored" - }, - "requirements-plain-vendored-pip-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "requirements.txt" - ], - "cwd": "/matrix//requirements-plain-vendored" - }, - "script-lock-hosted": { - "args": [ - "/bin//uv", - "lock", - "--script", - "example.py", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//script-direct-hosted" - }, - "script-lock-vendored": { - "args": [ - "/bin//uv", - "lock", - "--script", - "example.py", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//script-direct-vendored" - }, - "compile-pylock-hosted": { - "args": [ - "/bin//uv", - "pip", - "compile", - "requirements.in", - "--python-version", - "3.9", - "-o", - "pylock.toml" - ], - "cwd": "/matrix//pylock-direct-hosted" - }, - "compile-pylock-vendored": { - "args": [ - "/bin//uv", - "pip", - "compile", - "requirements.in", - "--python-version", - "3.9", - "-o", - "pylock.toml" - ], - "cwd": "/matrix//pylock-direct-vendored" - }, - "project-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//project-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//project-hosted" - }, - "project-hosted-export-requirements-txt": { - "args": [ - "/bin//uv", - "export", - "--frozen", - "--format", - "requirements-txt" - ], - "cwd": "/matrix//project-hosted" - }, - "project-hosted-export-pylock.toml": { - "args": [ - "/bin//uv", - "export", - "--frozen", - "--format", - "pylock.toml" - ], - "cwd": "/matrix//project-hosted" - }, - "project-hosted-lock-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//project-hosted" - }, - "project-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//project-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//project-vendored" - }, - "project-hosted-unfrozen-install": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//project-unfrozen-hosted" - }, - "project-hosted-lock-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--frozen" - ], - "cwd": "/matrix//project-hosted" - }, - "project-hosted-locked-install": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//project-unfrozen-hosted" - }, - "project-vendored-export-requirements-txt": { - "args": [ - "/bin//uv", - "export", - "--frozen", - "--format", - "requirements-txt" - ], - "cwd": "/matrix//project-vendored" - }, - "project-vendored-export-pylock.toml": { - "args": [ - "/bin//uv", - "export", - "--frozen", - "--format", - "pylock.toml" - ], - "cwd": "/matrix//project-vendored" - }, - "project-vendored-lock-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--frozen", - "--offline" - ], - "cwd": "/matrix//project-vendored" - }, - "project-vendored-frozen-sync-root-build-networked": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//project-vendored" - }, - "project-vendored-locked-install": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//project-unfrozen-vendored" - }, - "project-vendored-unfrozen-install": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//project-unfrozen-vendored" - }, - "variant-tool-uv-dev-hosted-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-tool-uv-dev-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-hosted-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-hosted-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-hosted-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-vendored-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-tool-uv-dev-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-tool-uv-dev-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-tool-uv-dev-vendored-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-tool-uv-dev-vendored-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-tool-uv-dev-vendored-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-dependency-groups-hosted-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-dependency-groups-hosted" - }, - "variant-dependency-groups-vendored-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-dependency-groups-vendored" - }, - "variant-extras-duplicate-hosted-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-extras-duplicate-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-hosted-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-hosted-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-hosted-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-vendored-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-extras-duplicate-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-extras-duplicate-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-extras-duplicate-vendored-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-extras-duplicate-vendored-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-extras-duplicate-vendored-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-constraints-hosted-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-vendored-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-transitive-hosted-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-transitive-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-hosted-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-hosted-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-hosted-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-vendored-lock": { - "args": [ - "/bin//uv", - "lock", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-transitive-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-transitive-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-transitive-vendored-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-transitive-vendored-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-transitive-vendored-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-constraints-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-constraints-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-hosted-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-hosted-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-hosted-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-constraints-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-constraints-vendored-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-constraints-vendored-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-constraints-vendored-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "project-hosted-lock-sync-variant-3": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--frozen", - "--no-install-project" - ], - "cwd": "/matrix//project-hosted" - }, - "project-vendored-lock-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--frozen", - "--no-install-project", - "--offline" - ], - "cwd": "/matrix//project-vendored" - }, - "project-hosted-locked-install-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//project-unfrozen-hosted" - }, - "project-hosted-unfrozen-install-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//project-unfrozen-hosted" - }, - "project-vendored-locked-install-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//project-unfrozen-vendored" - }, - "project-vendored-unfrozen-install-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//project-unfrozen-vendored" - }, - "variant-tool-uv-dev-hosted-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-hosted-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-hosted-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-tool-uv-dev-hosted" - }, - "variant-tool-uv-dev-vendored-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-tool-uv-dev-vendored-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-tool-uv-dev-vendored-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-tool-uv-dev-vendored" - }, - "variant-extras-duplicate-hosted-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-hosted-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-hosted-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-extras-duplicate-hosted" - }, - "variant-extras-duplicate-vendored-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-extras-duplicate-vendored-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-extras-duplicate-vendored-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-extras-duplicate-vendored" - }, - "variant-constraints-hosted-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-hosted-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-hosted-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-constraints-hosted" - }, - "variant-constraints-vendored-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-constraints-vendored-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-constraints-vendored-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-constraints-vendored" - }, - "variant-transitive-hosted-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-hosted-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-hosted-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-transitive-hosted" - }, - "variant-transitive-vendored-frozen-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-transitive-vendored-locked-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "variant-transitive-vendored-plain-sync-variant-2": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-transitive-vendored" - }, - "requirements-hosted-export-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "requirements.txt" - ], - "cwd": "/matrix//export-requirements-hosted" - }, - "requirements-vendored-export-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "requirements.txt", - "--offline" - ], - "cwd": "/matrix//export-requirements-vendored" - }, - "variant-dependency-groups-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-dependency-groups-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-dependency-groups-hosted" - }, - "variant-dependency-groups-hosted-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-dependency-groups-hosted" - }, - "variant-dependency-groups-hosted-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-dependency-groups-hosted" - }, - "variant-dependency-groups-hosted-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-dependency-groups-hosted" - }, - "variant-dependency-groups-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//variant-dependency-groups-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//variant-dependency-groups-vendored" - }, - "variant-dependency-groups-vendored-frozen-sync": { - "args": [ - "/bin//uv", - "sync", - "--frozen", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-dependency-groups-vendored" - }, - "variant-dependency-groups-vendored-locked-sync": { - "args": [ - "/bin//uv", - "sync", - "--locked", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-dependency-groups-vendored" - }, - "variant-dependency-groups-vendored-plain-sync": { - "args": [ - "/bin//uv", - "sync", - "--python", - "/usr/bin/python3", - "--no-install-project" - ], - "cwd": "/matrix//variant-dependency-groups-vendored" - }, - "script-direct-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//script-direct-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//script-direct-hosted" - }, - "script-direct-hosted-install": { - "args": [ - "/bin//uv", - "run", - "--frozen", - "--python", - "/usr/bin/python3", - "--script", - "example.py" - ], - "cwd": "/matrix//script-direct-hosted" - }, - "script-direct-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//script-direct-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//script-direct-vendored" - }, - "script-direct-vendored-install": { - "args": [ - "/bin//uv", - "run", - "--offline", - "--frozen", - "--python", - "/usr/bin/python3", - "--script", - "example.py" - ], - "cwd": "/matrix//script-direct-vendored" - }, - "script-hosted-locked-install": { - "args": [ - "/bin//uv", - "run", - "--locked", - "--python", - "/usr/bin/python3", - "--script", - "example.py" - ], - "cwd": "/matrix//script-unfrozen-hosted" - }, - "script-hosted-unfrozen-install": { - "args": [ - "/bin//uv", - "run", - "--python", - "/usr/bin/python3", - "--script", - "example.py" - ], - "cwd": "/matrix//script-unfrozen-hosted" - }, - "script-vendored-locked-install": { - "args": [ - "/bin//uv", - "run", - "--locked", - "--python", - "/usr/bin/python3", - "--script", - "example.py" - ], - "cwd": "/matrix//script-unfrozen-vendored" - }, - "script-vendored-unfrozen-install": { - "args": [ - "/bin//uv", - "run", - "--python", - "/usr/bin/python3", - "--script", - "example.py" - ], - "cwd": "/matrix//script-unfrozen-vendored" - }, - "pylock-hosted-export-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "pylock.toml" - ], - "cwd": "/matrix//export-pylock-hosted" - }, - "pylock-vendored-export-sync": { - "args": [ - "/bin//uv", - "pip", - "sync", - "pylock.toml", - "--offline" - ], - "cwd": "/matrix//export-pylock-vendored" - }, - "pylock-direct-hosted-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//pylock-direct-hosted", - "--mode", - "hosted", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//pylock-direct-hosted" - }, - "pylock-direct-hosted-install": { - "args": [ - "/bin//uv", - "pip", - "sync", - "pylock.toml" - ], - "cwd": "/matrix//pylock-direct-hosted" - }, - "pylock-direct-vendored-socket-patch": { - "args": [ - "", - "scan", - "--cwd", - "/matrix//pylock-direct-vendored", - "--mode", - "vendored", - "--json", - "--yes", - "--no-telemetry" - ], - "cwd": "/matrix//pylock-direct-vendored" - }, - "pylock-direct-vendored-install": { - "args": [ - "/bin//uv", - "pip", - "--offline", - "sync", - "pylock.toml" - ], - "cwd": "/matrix//pylock-direct-vendored" - } - }, - "versions": [ - { - "version": "0.0.5", - "lockSchema": null, - "lockVersion": null, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 2, - "diagnostic": "error: Unexpected '.', expected '-c', '-e', '-r' or the start of a requirement in `requirements.txt` at position 144\n" - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 2, - "diagnostic": "error: Unexpected '.', expected '-c', '-e', '-r' or the start of a requirement in `requirements.txt` at position 126\n" - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - } - ] - }, - { - "version": "0.1.0", - "lockSchema": null, - "lockVersion": null, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 2, - "diagnostic": "error: Unexpected '.', expected '-c', '-e', '-r' or the start of a requirement in `requirements.txt` at position 144\n" - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 2, - "diagnostic": "error: Unexpected '.', expected '-c', '-e', '-r' or the start of a requirement in `requirements.txt` at position 126\n" - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - } - ] - }, - { - "version": "0.1.23", - "lockSchema": null, - "lockVersion": null, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 2, - "diagnostic": "error: Unexpected '.', expected '-c', '-e', '-r' or the start of a requirement at requirements.txt:3:1\n" - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 2, - "diagnostic": "error: Unexpected '.', expected '-c', '-e', '-r' or the start of a requirement at requirements.txt:3:1\n" - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - } - ] - }, - { - "version": "0.1.24", - "lockSchema": null, - "lockVersion": null, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'lock'\n\n tip: a similar subcommand exists: 'uv pip compile'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - } - ] - }, - { - "version": "0.1.44", - "lockSchema": null, - "lockVersion": null, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 101, - "diagnostic": "warning: `uv lock` is experimental and may change without warning.\nUsing Python 3.14.3 interpreter at: /opt/homebrew/opt/python@3.14/bin/python3.14\nCreating virtualenv at: .venv\nResolved 2 packages in 538ms\nthread 'main' panicked at crates/uv-resolver/src/lock.rs:304:40:\nnot yet implemented\nnote: run with `RUST_BACKTRACE=1` environment variable to display a backtrace\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - } - ] - }, - { - "version": "0.1.45", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.0", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.5", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.6", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.17", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.18", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.34", - "lockSchema": "distribution", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": null, - "vendored": null - }, - "dependency-groups": { - "hosted": null, - "vendored": null - }, - "extras-duplicate": { - "hosted": null, - "vendored": null - }, - "constraints": { - "hosted": null, - "vendored": null - }, - "transitive": { - "hosted": null, - "vendored": null - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 1, - "vendorSummary": { - "applied": 0, - "failed": 1 - }, - "vendorErrors": [ - { - "action": "failed", - "purl": "pkg:pypi/urllib3@1.26.18?artifact_id=py2-py3-none-any-whl", - "errorCode": "pypi_uv_legacy_lock_unsupported", - "error": "uv `[[distribution]]` lockfiles (uv < 0.2.35, experimental `uv lock`) cannot carry a portable local wheel: `--locked` rejects relative paths and `uv lock`/`uv sync` rewrite them to absolute ones; upgrade to uv >=0.2.35 for native vendoring, or use a requirements.txt installation" - } - ] - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.2.35", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nerror: Failed to prepare distributions\n Caused by: Failed to fetch wheel: socket-uv-patch-fixture @ file:///matrix/0.2.35/project-vendored\n Caused by: Failed to build: `socket-uv-patch-fixture @ file:///matrix/0.2.35/project-vendored`\n Caused by: Failed to install requirements from setup.py build (resolve)\n Caused by: No solution found when resolving: setuptools>=40.8.0\n Caused by: Because setuptools was not found in the cache and you require setuptools>=40.8.0, we can conclude that the requirements are unsatisfiable.\n\nhint: Packages were unavailable because the network was disabled\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-frozen-sync-root-build-networked", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 194ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 334ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.2.36", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nerror: Failed to prepare distributions\n Caused by: Failed to fetch wheel: socket-uv-patch-fixture @ file:///matrix/0.2.36/project-vendored\n Caused by: Failed to build: `socket-uv-patch-fixture @ file:///matrix/0.2.36/project-vendored`\n Caused by: Failed to install requirements from setup.py build (resolve)\n Caused by: No solution found when resolving: setuptools>=40.8.0\n Caused by: Because setuptools was not found in the cache and you require setuptools>=40.8.0, we can conclude that the requirements are unsatisfiable.\n\nhint: Packages were unavailable because the network was disabled\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-frozen-sync-root-build-networked", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 339ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 211ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.2.37", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nerror: Failed to prepare distributions\n Caused by: Failed to fetch wheel: socket-uv-patch-fixture @ file:///matrix/0.2.37/project-vendored\n Caused by: Failed to install requirements from setup.py build (resolve)\n Caused by: No solution found when resolving: setuptools>=40.8.0\n Caused by: Because setuptools was not found in the cache and you require setuptools>=40.8.0, we can conclude that your requirements are unsatisfiable.\n\nhint: Packages were unavailable because the network was disabled\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-frozen-sync-root-build-networked", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nwarning: `uv.sources` is experimental and may change without warning\nResolved 2 packages in 7ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nwarning: `uv.sources` is experimental and may change without warning\nResolved 2 packages in 3ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 349ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "warning: `uv sync` is experimental and may change without warning\nUsing Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 539ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.3.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nerror: Failed to prepare distributions\n Caused by: Failed to fetch wheel: socket-uv-patch-fixture @ file:///matrix/0.3.0/project-vendored\n Caused by: Failed to install requirements from setup.py build (resolve)\n Caused by: No solution found when resolving: setuptools>=40.8.0\n Caused by: Because setuptools was not found in the cache and you require setuptools>=40.8.0, we can conclude that your requirements are unsatisfiable.\n\nhint: Packages were unavailable because the network was disabled. When the network is disabled, registry packages may only be read from the cache.\n" - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-frozen-sync-root-build-networked", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 5ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 6ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 642ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 347ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.3.5", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 5ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 4ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 700ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 777ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.4.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: unrecognized subcommand 'export'\n\nUsage: uv [OPTIONS] \n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 6ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 8ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 541ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 1.16s\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.4.1", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "unsupported", - "vendored": "unsupported" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 4ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 2 packages in 6ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 1.03s\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using Python 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtualenv at: .venv\nResolved 6 packages in 517ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.4.30", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 2 packages in 18ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 2 packages in 8ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 6 packages in 321ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 6 packages in 312ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.5.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": [ - "fail", - [ - "locked" - ] - ], - "vendored": [ - "fail", - [ - "locked" - ] - ] - }, - "transitive": { - "hosted": [ - "fail", - [ - "locked", - "plain" - ] - ], - "vendored": [ - "fail", - [ - "locked", - "plain" - ] - ] - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 2 packages in 3ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 2 packages in 5ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 6 packages in 346ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 2, - "lockUnchanged": true, - "diagnostic": "Using CPython 3.9.6 interpreter at: /Applications/Xcode.app/Contents/Developer/usr/bin/python3\nCreating virtual environment at: .venv\nResolved 6 packages in 297ms\nerror: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. To update the lockfile, run `uv lock`.\n" - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": false, - "installedResponseSha256": "50f80b9a71e3e33ef56671fc8af60eca77004e27d33b0f4542e914a839dc9027", - "installedPatch": false - } - ] - }, - { - "version": "0.5.16", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "script-lock-vendored", - "exitCode": 2, - "diagnostic": "error: unexpected argument '--script' found\n\nUsage: uv lock [OPTIONS]\n\nFor more information, try '--help'.\n" - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.5.17", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.5.31", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": null, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.6.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 1, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": false - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.6.14", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 1, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 2, - "diagnostic": "error: invalid value 'pylock.toml' for '--format '\n [possible values: requirements-txt]\n\nFor more information, try '--help'.\n" - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 2, - "formatSupported": false, - "diagnostic": "error: TOML is not a supported output format for `uv pip compile` (only `requirements.txt`-style output is supported)\n" - }, - { - "command": "compile-pylock-vendored", - "exitCode": 2, - "formatSupported": false, - "diagnostic": "error: TOML is not a supported output format for `uv pip compile` (only `requirements.txt`-style output is supported)\n" - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.6.15", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 2, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.6.17", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 2, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.7.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 2, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.7.22", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 2, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.8.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 2, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.8.3", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 2, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.8.4", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.8.24", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.9.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.9.30", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.10.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.10.12", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.11.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.11.33", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.12.0", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - }, - { - "version": "0.12.15", - "lockSchema": "package", - "lockVersion": 1, - "lockRevision": 3, - "variants": { - "tool-uv-dev": { - "hosted": "pass", - "vendored": "pass" - }, - "dependency-groups": { - "hosted": "pass", - "vendored": "pass" - }, - "extras-duplicate": { - "hosted": "pass", - "vendored": "pass" - }, - "constraints": { - "hosted": "pass", - "vendored": "pass" - }, - "transitive": { - "hosted": "pass", - "vendored": "pass" - } - }, - "observations": [ - { - "command": "lock", - "exitCode": 0 - }, - { - "command": "project-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "project-hosted-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-hosted-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-hosted-lock-sync-variant-3", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "project-vendored-export-requirements-txt", - "exitCode": 0 - }, - { - "command": "project-vendored-export-pylock.toml", - "exitCode": 0 - }, - { - "command": "project-vendored-lock-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain", - "exitCode": 0 - }, - { - "command": "requirements-plain-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "requirements.txt" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "requirements-plain-hosted-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-plain-variant-2", - "exitCode": 0 - }, - { - "command": "requirements-plain-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "requirements-plain-vendored-pip-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-hosted-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "requirements-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "pylock-vendored-export-sync", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-hosted", - "exitCode": 0 - }, - { - "command": "script-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "example.py", - "example.py.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "script-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-lock-vendored", - "exitCode": 0 - }, - { - "command": "script-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "script-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-hosted", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-hosted-socket-patch", - "exitCode": 0, - "rewrittenFiles": [ - "pylock.toml" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "pylock-direct-hosted-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "compile-pylock-vendored", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "pylock-direct-vendored-socket-patch", - "exitCode": 0, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "pylock-direct-vendored-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-hosted-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-locked-install-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "project-vendored-unfrozen-install-variant-2", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-hosted-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-locked-install", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "script-vendored-unfrozen-install", - "exitCode": 0, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-tool-uv-dev-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-tool-uv-dev-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-tool-uv-dev-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-tool-uv-dev-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-dependency-groups-hosted-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-hosted-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-dependency-groups-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-dependency-groups-vendored-frozen-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-locked-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-dependency-groups-vendored-plain-sync", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-extras-duplicate-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-extras-duplicate-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-extras-duplicate-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-extras-duplicate-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-constraints-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-constraints-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-constraints-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-constraints-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-hosted-socket-patch", - "exitCode": 0, - "patchInLock": true, - "rewrittenFiles": [ - "pyproject.toml", - "uv.lock" - ], - "redirected": 1, - "warnings": [] - }, - { - "command": "variant-transitive-hosted-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-hosted-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-lock", - "exitCode": 0, - "formatSupported": true - }, - { - "command": "variant-transitive-vendored-socket-patch", - "exitCode": 0, - "patchInLock": true, - "vendorSummary": { - "applied": 1, - "failed": 0 - }, - "vendorErrors": [] - }, - { - "command": "variant-transitive-vendored-frozen-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-locked-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - }, - { - "command": "variant-transitive-vendored-plain-sync-variant-2", - "exitCode": 0, - "lockUnchanged": true, - "installedResponseSha256": "21d9a7810de52973c88d9170f437e98921456bce445ab0618576987478a6a6e4", - "installedPatch": true - } - ] - } - ] -} diff --git a/docs/testing/vendored-production-e2e.md b/docs/testing/vendored-production-e2e.md index e7d813302..a31f00545 100644 --- a/docs/testing/vendored-production-e2e.md +++ b/docs/testing/vendored-production-e2e.md @@ -1,209 +1,76 @@ -# Vendored-mode production e2e +# Vendored production tests -`crates/socket-patch-cli/tests/e2e_vendored_production.rs` is the vendored-mode -counterpart to [`hosted-production-e2e.md`](./hosted-production-e2e.md). The -synthetic `e2e_vendor_*_build.rs` capstones prove the vendoring *mechanism* with -a hand-staged `.socket/` blob and `vendor --offline`; they never contact -production. This suite is the opposite: it drives `scan --mode vendored` against -the **real** Socket production service and the **real** upstream registries with -**no mocking anywhere**, on the anonymous **free public proxy** (no API token). +[`e2e_vendored_production.rs`](../../crates/socket-patch-cli/tests/e2e_vendored_production.rs) +uses the public patch service and real upstream registries to test committed +patched artifacts. It complements the [hosted suite](hosted-production-e2e.md) +and controlled-input vendor tests. ## What it proves -For each ecosystem × package manager: - -1. install a pinned, known-vulnerable dependency from its **real** upstream - registry with the **real** package manager; -2. assert the installed bytes are pristine (anti-vacuity); -3. `socket-patch scan --mode vendored --json --yes` — resolves a free patch from - `patches-api.socket.dev`, materializes the patched package into the - committable `.socket/vendor///` tree, and rewires the lockfile / - manifest to consume it; -4. assert the vendor landed (`summary.applied >= 1`, `failed == 0`, expected - patch UUID present, artifact on disk, lock rewired); -5. **DELIVERY proof** — copy ONLY the committable files (project manifest + - lockfile + `.socket/` + any PM config) into a fresh dir, point every cache - var at a fresh EMPTY dir, run the package manager's clean-install offline, - and assert the installed bytes are the VENDORED (patched) bytes, NOT the - pristine registry bytes; -6. idempotency (a second run is an `already_vendored` no-op with a byte-stable - lock) and `vendor --revert` byte-restores. - -Step 5 is the point. It is the only place in this repo where a third-party -package manager installs, from a genuinely cold cache and with only the -committable files, a package vendored from a **real** Socket production patch. - -This suite proves **byte delivery** — the bytes the vendored patch produced are -the bytes the package manager installs. It does NOT assert CVE efficacy; -whether the fix content actually closes the advisory is a separate concern, and -several production patches are byte-valid but that is a different question. This -matches how the `e2e_vendor_*_build.rs` capstones assert. - -## Required production patches - -Pinned to these free-tier patches; they must stay published on -`patches-api.socket.dev`. `preflight_required_patches_are_published` checks all -three every run and fails first with the offending PURL named. - -| Ecosystem | PURL | Patch UUID | Marker in the patched bytes | -|-----------|------|------------|-----------------------------| -| npm | `pkg:npm/minimist@1.2.2` | `80630680-4da6-45f9-bba8-b888e0ffd58c` | `Socket Community Patch` header | -| PyPI | `pkg:pypi/urllib3@1.26.18` | one of three (picked by the CLI's `api::ranking`; the suite accepts any) | `Socket Community Patch` header | -| RubyGems | `pkg:gem/activestorage@6.0.3` | any of the `GEM_PATCHES` table (each patch marks a different file): the same 6 live UUIDs as the hosted doc, including `9c2b4925` and the merged `01019627` that v5 ranking prefers | `Socket Community Patch` header | - -If a required patch is withdrawn, update the catalog constants at the top of -`e2e_vendored_production.rs` **and** the table above (same procedure as the -hosted suite). - -## Coverage: PM × proof - -| Package manager | Fixture | Delivery install (cold, offline, committable-only) | Status | -|-----------------|---------|-----------------------------------------------------|--------| -| npm | minimist@1.2.2 | `npm ci` | ✅ full | -| pnpm | minimist@1.2.2 | `pnpm install --frozen-lockfile --offline` | ✅ full | -| yarn classic | minimist@1.2.2 | `yarn install --frozen-lockfile --offline` | ✅ full | -| yarn berry (node-modules) | minimist@1.2.2 | `yarn install --immutable --check-cache` | ✅ full | -| bun (text lockfile) | minimist@1.2.2 | `bun install --frozen-lockfile` | ✅ full | -| vlt 1.2.0 (`vlt-lock.json`) | minimist@1.2.2 | fresh checkout, `vlt ci` (lock byte-stable) | ✅ full (`vlt_pinned_matrix_production_vendored_install_proof`) | -| pip (requirements.txt) | urllib3@1.26.18 | `pip install --no-index -r requirements.txt` | ✅ full | -| uv (uv.lock) | urllib3@1.26.18 | `uv sync --frozen --offline` | ✅ full | -| bundler | activestorage@6.0.3 | frozen `bundle install`, fresh empty `BUNDLE_PATH` | ✅ full | -| go | — | — | zero-patch assertion (no free golang patches) | -| deno | — | — | negative assertion (unsupported) | -| cargo / maven / nuget / composer | — | — | canary (no free production patches) | - -Cargo sat in the ✅-full rows until 2026-09-01: the leg vendored a pinned crate -as a `[patch.crates-io]` path dep and proved delivery with -`cargo fetch --offline --locked` from an empty `CARGO_HOME`. Production's free -cargo tier emptied on 2026-08-28 (the pinned patches were deleted server-side, -leaving zero live free patches for any cargo crate), so the leg was demoted to -`canary_unpublished_vendored_ecosystems` — deliberately dropping the cargo -install-proof coverage. To re-promote: pick a live free cargo patch and follow -the withdrawn-patch procedure in the -[hosted doc](./hosted-production-e2e.md#if-a-required-patch-is-withdrawn); the -git history of this demotion shows every piece to restore in both production -suites. - -## Known issues this suite surfaced - -All were found against real production + real toolchains; none is a test bug. -The first two are fixed; the third is mitigated CLI-side (the served artifact -is still defective server-side). - -### 1. `pnpm` >= 11 — vendored `overrides` land in the wrong file (CLI) — FIXED - -pnpm 11 stopped reading `overrides` from `package.json`'s `pnpm` field — it -moved to `pnpm-workspace.yaml` (https://pnpm.io/settings). The CLI used to write -only `package.json` `pnpm.overrides`, so pnpm 11 ignored it and a frozen install -refused with `ERR_PNPM_LOCKFILE_CONFIG_MISMATCH`, even though the vendored -tarball and lock were correct (the lockfile passes pnpm's supply-chain policy). - -**Fixed** (`fix/pnpm11-overrides-location`): the pnpm vendor backend now -mirrors the same versioned `@` → `file:` override into -`pnpm-workspace.yaml` (creating the file with a root-only `packages: ['.']` -list — pnpm 9 refuses a workspace file with no `packages` field — when the -project has none), alongside the existing `package.json` `pnpm.overrides` for -pnpm 9/10. The committable set installs cleanly on pnpm 9/10/11 with no config -mismatch, and `vendor --revert` deletes a file it created (or splices its -override back out of one it edited). This leg now asserts the frozen install -succeeds directly, with no workaround. - -### 2. `gem` — vendoring the platform-qualified purl was unsupported (CLI) — FIXED - -`scan --mode vendored` resolved and downloaded the activestorage patch, but the -vendor backend refused the platform-qualified purl -(`pkg:gem/activestorage@…?platform=ruby` — the spelling production publishes) -with `platform_gem_unsupported`, so `summary.applied == 0`, `failed == 1`, and -the run exited non-zero with `"status": "partial_failure"`. - -**Fixed** (PR #172): the gate in `vendor/gem.rs` now refuses only non-empty, -non-`ruby` platform qualifiers — `?platform=ruby` is the portable default and -vendors like a bare purl. The suite's original pin -(`activestorage@7.0.2.2` / `2535d43d-67ce-4944-be27-c19e113997fb`) was -withdrawn on 2026-08-14; the 2026-08-18 catalog republish REPLACED it, and the -suite was re-pinned to `activestorage@6.0.3` / -`15e960b5-f432-4b6c-b8aa-534a2b419323`. The vendor succeeds live and the leg -was upgraded to the full fresh-dir `bundle install` delivery proof -(`gem_bundler_vendored_install_proof`), retiring its failure-tolerance branch -and its `SOCKET_PATCH_VENDORED_E2E_GEM_STRICT` knob. - -### 3. `gem` — the served gem-stub gemspec is invalid (SERVER; CLI mitigated) - -Discovered 2026-08-19 while upgrading the gem leg to a full delivery proof: -the gem-stub-gemspec artifact production serves is invalid — it is missing -`summary`/`authors`, which rubygems validation requires — so writing it -verbatim makes bundler reject the vendored `path:` source and -`bundle install` exit 1 on every bundler major. - -**Mitigated CLI-side**: the gem vendor backend now validates BOTH stub sources -at the write choke point (a conservative textual check matched to what -rubygems 3.3–3.6 actually hard-fails — empirically verified in the bundler-era -docker images). `--vendor-source auto` detects the served defect, warns -(`vendor_prebuilt_stub_invalid`), and falls back to the local build — which is -how `gem_bundler_vendored_install_proof` passes against production today — -while explicit `--vendor-source service` refuses with -`vendor_prebuilt_stub_invalid`. When the gem is also not installed (no local -stub to derive), `auto` refuses with the same code, the served defect named, -and the install-the-gem remedy; a corrupted LOCAL `specifications/` stub -refuses `gem_spec_invalid`. Re-vendoring a project that committed a defective -stub pre-hardening re-validates the ON-DISK stub and rebuilds the artifact -with a valid one. The leg's route-attribution assertion (exactly one of -`vendor_prebuilt_downloaded` / `vendor_prebuilt_stub_invalid`) auto-retires -the fallback expectation once the depscan stub-generator fix deploys and the -rebuilt artifacts serve valid stubs — the same leg then exercises the service -artifact directly. +Each install-proof case starts with pristine installed bytes, runs +`scan --mode vendored`, and checks the artifact, ledger, and dependency edits. +It copies only committable project files to a fresh checkout, isolates caches, +installs from the committed artifacts, and checks the patched bytes. Reruns, +reversal, and manifest-free VEX exercise the rest of the lifecycle. + +This tests patch delivery, not exploit efficacy. The fixture determines which +other dependencies must be available during installation; vendoring patched +packages does not itself make every dependency offline. + +## Catalog fixtures and coverage + +The test source defines required PURLs, accepted patch UUIDs, byte markers, and +preflight checks. It shares the npm, PyPI, and RubyGems fixture families with the +hosted suite. Follow its [withdrawn-patch procedure](hosted-production-e2e.md#if-a-required-patch-is-withdrawn) +when the catalog changes, updating both suites. + +| Coverage | Cases | +| --- | --- | +| Native production installs | npm, pnpm, Yarn Classic, Yarn Berry with node-modules, Bun text locks, vlt, pip requirements, uv, and Bundler | +| Catalog canaries | Cargo, Maven, NuGet, and Composer; require a published free fixture before adding full install proofs | +| Go / Deno | Catalog/unsupported-mode assertions, not production vendor install proofs | + +The vlt case installs a committed directory artifact with `vlt ci`. The CLI +decodes the service download before vendoring it, so the hosted vlt +[serve-encoding gate](hosted-production-e2e.md#vlt-the-serve-encoding-gate) does +not prevent this proof. Per-release coverage lives in the +[compatibility guides](README.md#package-manager-guides). + +### RubyGems artifact validation + +A vendored Bundler path source needs a valid stub gemspec. The CLI validates +service and local stubs before writing them. An invalid service stub causes +`--vendor-source auto` to try a local build when possible; +`--vendor-source service` refuses with `vendor_prebuilt_stub_invalid`. +A missing local source can prevent that fallback. The production test accepts +and checks the actual acquisition route, so it does not assume a previously +observed server defect is still present. ## Running ```sh -# everything, soft-skipping legs whose toolchain is absent -cargo test -p socket-patch-cli --test e2e_vendored_production -- --ignored --test-threads=1 +cargo test --locked -p socket-patch-cli --test e2e_vendored_production -- \ + --ignored --test-threads=1 -# CI: turn every "toolchain missing" soft-skip into a hard failure +# Require the toolchains instead of allowing local skips: SOCKET_PATCH_VENDORED_E2E_STRICT=1 \ - cargo test -p socket-patch-cli --test e2e_vendored_production -- --ignored --test-threads=1 + cargo test --locked -p socket-patch-cli --test e2e_vendored_production -- \ + --ignored --test-threads=1 ``` -The suite is `#[ignore]`-gated, so it stays out of the `test` and `e2e` jobs and -runs only where it is explicitly asked for. `--test-threads=1` keeps the real -installs from contending on the shared cache sandbox. - -The bun leg (`bun_vendored_install_proof`) is therefore on-demand production -coverage. The per-PR real-Bun evidence for vendored mode is the hermetic -`e2e_vendor_bun_build` suite in `ci.yml`'s `e2e` matrix (Bun 1.4.2 on three -OSes, 1.1.45 and 1.2.23 on Linux) plus the production native matrix in -`bun-compatibility.yml` (16 releases × 3 OS in hosted and vendored mode — -vendored is manifest-free) — see [Bun compatibility](bun-compatibility.md). - -The vlt leg vendors the service's directory artifact into the D19 layout -(`.socket/vendor/npm//minimist-1.2.2/node_modules/minimist`) and proves -it with a fresh `vlt ci`. The CLI's own download decodes the transfer, so the -serve-encoding gate that blocks hosted vlt (see the -[hosted doc](hosted-production-e2e.md#vlt-the-serve-encoding-gate)) does not -apply. CI runs it in the `hosted-e2e` job -(`--test e2e_vendored_production -- --include-ignored vlt_pinned_matrix`, -through `scripts/check-vlt-legs.py`); the per-release evidence is in -[vlt compatibility](vlt-compatibility.md). - -### Environment knobs +The suite is opt-in. Single-threaded execution avoids competing native installs. +It clears ambient Socket credentials and disables persisted login; no API token +is needed. | Variable | Effect | -|----------|--------| -| `SOCKET_PATCH_VENDORED_E2E_STRICT=1` | Turn every "toolchain missing" soft-skip into a hard failure. | -| `SOCKET_PATCH_VLT_E2E_JS` / `SOCKET_PATCH_VLT_E2E_VERSION` | The vlt release the vlt leg runs (`node `, exact `--version`). | -| `SOCKET_PATCH_VENDORED_E2E_CANARY_STRICT=1` | Fail when cargo/maven/nuget/composer gain their first free published patch. | - -The suite forces `SOCKET_NO_CONFIG=true` and scrubs every ambient `SOCKET_*` -var, planting hostile seeds so a dropped scrub reddens the suite instead of -letting a developer's socket-cli login move the run onto the org catalog. No API -token is used. - -### Toolchains - -`npm`, `pnpm`, `corepack` (yarn classic + berry), `bun`, `vlt` (Node ≥ 22.22), `uv`, `python3` (pip), -`ruby` + `bundle`, `go`. - -### Network egress - -`patches-api.socket.dev`, `patch.socket.dev`, `registry.npmjs.org`, `pypi.org`, -`files.pythonhosted.org`, `rubygems.org`. +| --- | --- | +| `SOCKET_PATCH_VENDORED_E2E_STRICT=1` | Fail instead of skipping missing required toolchains | +| `SOCKET_PATCH_VENDORED_E2E_CANARY_STRICT=1` | Fail when a watched ecosystem gains a free fixture | +| `SOCKET_PATCH_VLT_E2E_JS` / `SOCKET_PATCH_VLT_E2E_VERSION` | Select the version-pinned vlt executable | + +Tools include npm, pnpm, Corepack for Yarn, Bun, vlt, uv, Python/pip, Ruby/Bundler, +and Go. Networked fixture preparation requires Socket's API and patch server plus +npm, PyPI, and RubyGems. CI versions and triggers are defined in the +[main workflow](../../.github/workflows/ci.yml) and package-manager workflows. +The main `hosted-e2e` job includes the vendored vlt proof; it does not imply that +every vendored production case ran. diff --git a/docs/testing/yarn-berry-compatibility.md b/docs/testing/yarn-berry-compatibility.md index 7c36cb69b..5bd45eee3 100644 --- a/docs/testing/yarn-berry-compatibility.md +++ b/docs/testing/yarn-berry-compatibility.md @@ -37,49 +37,20 @@ core unit tests. ## Line endings -yarn berry keeps one line ending per file, chosen by the same function for -the lockfile and every manifest. At tag `@yarnpkg/cli/4.12.0` (the same code -ships at 4.0.0 and 4.18.0; the published 3.8.7, 4.0.2, 4.6.0, 4.9.2 and -4.18.0 bundles carry it verbatim, and 2.4.3 applies the same rule through -`changeFilePromise`): - -- `packages/yarnpkg-fslib/sources/FakeFS.ts` (lines 799–812): - `getEndOfLine(content)` returns `os.EOL` when `content` has no line break — - the file is new — and otherwise `\r\n` only when CRLF breaks strictly - outnumber LF ones (a tie is LF); `normalizeLineEndings(original, next)` - respells every break of `next` that way. -- `packages/yarnpkg-core/sources/Project.ts`: `persistLockfile` (lines - 2014–2033) writes the generated lock through `normalizeLineEndings` against - the current file; the `--immutable` check (lines 1789–1858) fails with - YN0028 whenever `normalizeLineEndings(initialLockfile, generateLockfile())` - differs from the file — so a uniformly CRLF lock passes, while a lock with - mixed endings (or a BOM, which the re-render never writes) always fails. -- `packages/yarnpkg-core/sources/Workspace.ts` (lines 217–229): - `persistManifest` writes `JSON.stringify(data, null, indent) + "\n"` through - `changeFilePromise(…, {automaticNewlines: true})`, the same rule, after every - install (`Project.ts` line 1881, `--immutable` included). - `Manifest.loadFromText` strips a BOM when reading (`Manifest.ts` lines - 135–146 and 984–990); the rewrite never writes one back. -- `packages/yarnpkg-parsers/sources/syml.ts`: `parseSyml` reads the lock with - js-yaml, which accepts CRLF. - -So on Windows every yarn berry project starts CRLF: the first `yarn install` -writes a CRLF `yarn.lock`, and a `package.json` yarn pretty-prints for the -first time (any compact one) comes back CRLF. On macOS and Linux both are LF. -An existing file keeps its majority ending on every OS. Git adds its own -path to CRLF: `core.autocrlf=true` (the Git for Windows installer's default) -checks LF-committed text out as CRLF, and so does `core.autocrlf=true` or a -`text eol=crlf` attribute on macOS and Linux; a lock committed with CRLF stays -CRLF in every checkout. +Yarn Berry preserves a file's majority line ending and uses the platform's +ending for a new file. Uniform LF and CRLF files are supported. Mixed line +endings can fail Yarn's immutable-install check; Socket Patch refuses mixed +lockfiles before rewriting them. The suites below cover native and forced CRLF +checkouts. What socket-patch does with those files: | | hosted (`yarn.lock`) | vendored (`yarn.lock` + root `package.json`) | | --- | --- | --- | -| uniformly LF or CRLF | rewritten in the file's own ending; ledger fragments recorded as on disk | lock entry spliced in the file's ending; `package.json` re-serialized in its own layout (BOM, indent, ending, trailing newline) | +| uniformly LF or CRLF | rewritten in the file's own ending; no hosted ledger | lock entry spliced in the file's ending; `package.json` re-serialized in its own layout (BOM, indent, ending, trailing newline) | | leading BOM | kept | kept, both files | | mixed CRLF / LF, or a bare CR | refused untouched: `redirect_yarn_berry_mixed_line_endings` | refused before any write: `vendor_yarn_berry_mixed_line_endings` | -| revert (`rollback`, `remove`, takeovers) | byte-exact; a ledger recorded before a uniform LF ↔ CRLF checkout flip is replayed respelled; a mixed lock refuses as drift | byte-exact; a lock mixed after vendoring gets the restored entry in the terminator of the entry it replaces | +| revert (`rollback`, `remove`, takeovers) | upstream entries reconstructed from registry metadata; mixed endings refuse as drift | byte-exact; a lock mixed after vendoring gets the restored entry in the terminator of the entry it replaces | | mode takeover into this mode | the berry gates (line endings, `cacheKey`, `compressionLevel`) run BEFORE the vendored wiring is reverted; a refused purl stays vendored, byte-identical | the backend's project gates (both files' line endings, `cacheKey`, `compressionLevel`) run BEFORE the hosted redirect is reverted; a refused purl stays hosted, byte-identical | Every reader — manifest-less `vex`, the lockfile inventory, the npm flavor diff --git a/docs/usage.md b/docs/usage.md new file mode 100644 index 000000000..f9d92256a --- /dev/null +++ b/docs/usage.md @@ -0,0 +1,195 @@ +# Using Socket Patch + +Start with the [README quick start](../README.md#quick-start). This guide covers +selection, automation, offline preparation, attestations, and recovery. Detailed +flags, response fields, and diagnostic codes live in the +[CLI contract](../crates/socket-patch-cli/CLI_CONTRACT.md). + +## Select patches + +A bare `scan` applies hosted patches without prompting. Use `--dry-run` to inspect +what it would change, and `--json` for a machine-readable result: + +```sh +socket-patch scan --dry-run --json +socket-patch scan --package lodash --package pkg:pypi/requests +socket-patch scan --ecosystems npm,pypi +socket-patch scan apps/web apps/api +``` + +Package filters accept names or PURLs, with or without an exact version, and can be +repeated or comma-separated. Hosted and vendored PATH arguments name project +directories; quote globs to let the CLI expand them. Use one directory per invocation +with `--json`. Use one project and a distinct output path per `scan --vex` run. + +To make selection consistent across contributors and CI, commit a +[repository policy](configuration.md#repository-patch-policy). To target a specific +advisory or patch: + +```sh +socket-patch get CVE-2024-12345 --mode hosted +socket-patch get GHSA-xxxx-yyyy-zzzz --mode vendored +socket-patch get pkg:npm/lodash@4.17.20 --mode agent +``` + +Replace the example identifiers with the advisory or package you need. `get` also +accepts a patch UUID or package name. It defaults to hosted mode; `--save-only` and +global targeting default to agent mode instead. Hosted and vendored `get` do not +prompt. Agent-mode searches can offer an interactive choice. + +For each package version, automatic selection prefers the newest downloadable +merged patch (covering multiple advisories). Otherwise it selects by severity and +then publication date. Exact ties use tier and UUID. A rerun replaces a recorded +patch only with one that outranks it by merge status, severity, or date; tie-breaking +alone does not cause a replacement. The +[ranking contract](../crates/socket-patch-cli/CLI_CONTRACT.md#which-patch-gets-selected) +details selection and upgrades. + +## CI and automation + +Hosted and vendored projects use their normal dependency install step. Run scans +in a job that reviews and commits dependency-file changes, then install and verify +that result. Supply `SOCKET_API_TOKEN` through your CI secret store for organization +patches; a token is not needed for the free catalog. + +```sh +socket-patch scan --json > scan-result.json +``` + +Check the command's exit status before processing the result. A preview reports +patch availability; it does not fail merely because patches exist. JSON schemas +vary by command: use the [output reference](../crates/socket-patch-cli/CLI_CONTRACT.md#json-output-shapes) +rather than parsing human output. A pipeline that uses `jq` should preserve the +CLI's exit status, for example with Bash's `set -o pipefail`. + +`scan --max-new-patches 5` limits new patches per run; it does not limit updates to +existing patches. See [gradual rollout](configuration.md#gradual-rollout). + +## Vendoring and offline installs + +For an existing hosted project without an agent manifest: + +```sh +socket-patch vendor --dry-run +socket-patch vendor +``` + +`vendor` ejects the patches referenced by the project's hosted dependency files. +When an agent manifest exists, it uses that manifest's patch set. To discover and +vendor available patches in one run, use: + +```sh +socket-patch scan --mode vendored +``` + +Commit `.socket/vendor/`, including `state.json`, and every dependency or config +file the CLI reports. The ledger stores patch records, artifact fingerprints, and +reversal information. A checkout can install the committed patched packages without +Socket API access or a Socket Patch binary. + +This does not vendor unpatched dependencies. Provision those through your normal +mirror or package-manager cache, and test a clean offline install before relying +on an airgapped build. Integrity enforcement and cache behavior differ by package +manager; see [ecosystem support](ecosystems.md). + +Artifact acquisition is controlled by `--vendor-source`: + +| Value | Behavior | +| --- | --- | +| `auto` (default) | Use a service artifact when available, with local building as a fallback for eligible misses | +| `service` | Require a service artifact; refuse if unavailable | +| `build` | Build locally from available package and patch data | + +An integrity failure is refused rather than bypassed with a fallback. Offline +operation never fetches missing inputs. `repair` can restore missing or corrupt +artifacts from a valid ledger when sufficient inputs are available; it cannot +reconstruct a lost vendor ledger. Restore a lost ledger from version control. + +## OpenVEX + +Generate an attestation after installing the patched dependencies: + +```sh +socket-patch vex --output socket.vex.json +socket-patch vex --json --output socket.vex.json +``` + +The document marks vulnerabilities covered by verified Socket patches as +`not_affected`. It does not assess other vulnerabilities. A VEX-aware scanner must +be configured to consume the resulting file. + +| Patch mode | Evidence used by VEX | +| --- | --- | +| Agent | Installed patched files, checked against the manifest's hashes | +| Vendored | Committed artifacts and live dependency-file references | +| Hosted | Live hosted references and their integrity pins; installed copies are verified when available | + +Before installation, hosted VEX can describe the pinned dependency state without +verifying installed bytes. `scan --vex socket.vex.json` also emits hosted VEX before +installation; rerun standalone `vex` afterward. Impact statements include the patch +UUID; vendored and hosted statements add `(vendored)` and `(redirected)` respectively. +Exact strings are in the [provenance contract](../crates/socket-patch-cli/CLI_CONTRACT.md#vex-provenance-markers-contract). + +`vex` reads patch records from local state or fetches them from the API. Without a +local record, `--offline` omits the patch as `record_unavailable`. Commit the vendor +ledger when offline attestation is required. A reference no longer used by the +project is excluded even with `--no-verify`; that flag bypasses file-hash checks, +not reference validation. A patch record alone does not prove it is consumed. + +The product identifier is inferred from the Git origin or project metadata. Use +`--product ` when inference is unavailable or unsuitable. `--json` +requires `--output` so the document and command result do not share stdout. + +`scan`, `apply`, and `vendor` accept `--vex ` plus `--vex-product`, +`--vex-no-verify`, `--vex-doc-id`, and `--vex-compact`. Embedded generation is skipped +for `--dry-run`; an attestation failure makes the command fail even if patching +succeeded. See the [VEX contract](../crates/socket-patch-cli/CLI_CONTRACT.md#embedded-vex-apply---vex--scan---vex--vendor---vex) +for output and empty-project behavior. + +## Agent mode + +Agent mode records patches and applies them to installed files: + +```sh +socket-patch scan --mode agent +# Commit .socket/ and any project wiring the command reports. + +# After every fresh install, locally and in CI: +socket-patch apply +``` + +Once the required patch data is committed, `socket-patch apply --offline` works +without downloading it again. `get --save-only` records a patch without +applying it. `apply` skips packages owned by the vendor ledger. + +Deno uses agent mode. Cargo agent patches can affect a shared registry cache; Go +uses project-local copies and `replace` directives. Read the +[ecosystem caveats](ecosystems.md) before using agent mode in shared environments. +The removed `setup` command is covered in the [migration guide](migrating-to-v5.md). + +## Inspect, undo, and repair + +| Command | Effect | +| --- | --- | +| `list` | Show agent records, vendor records, and hosted pins; an empty project succeeds | +| `rollback [PURL\|UUID\|PATH]...` | Restore selected patches, or all patches when no target is given, and remove their local state | +| `remove ` | Restore and remove one patch | +| `vendor --revert` | Undo vendoring from its recorded edits and remove the vendored artifacts | +| `repair` | Restore missing patch data or damaged vendored artifacts and clean unused data | +| `scan --mode agent --prune` | Patch discovered packages and remove records for dependencies that left the project | + +Use `--dry-run` to preview. `rollback --preserve-state` and +`remove --preserve-state` restore dependencies while keeping local patch records +and artifacts for later reuse. Hosted pins have no local state to preserve. +`remove --skip-rollback` removes tracking without restoring installed files and +cannot be combined with `--preserve-state`. + +Hosted reversal resolves original registry entries; it does not replay saved file +snapshots. It needs upstream access and can refuse an unsupported or drifted entry. +Hosted binary `bun.lockb` reversal requires restoring the lockfile from version +control. Review and restore any companion manifest or registry-config changes too. +A package converted from hosted to vendored returns to upstream on `vendor --revert`. + +Vendored reversal preserves unrelated edits and refuses unsafe drift. Keep its +ledger with the artifacts. Full details and per-ecosystem restoration limits are in +the [rollback contract](../crates/socket-patch-cli/CLI_CONTRACT.md#rollback-command-contract-v50). diff --git a/scripts/backtest-uv.py b/scripts/backtest-uv.py index 38be686d2..308c2f7d2 100644 --- a/scripts/backtest-uv.py +++ b/scripts/backtest-uv.py @@ -1285,9 +1285,9 @@ def paragraph(text): f"untouched — and **{len(lock_changed)} changed the lock**. `--frozen` " f"never writes the lock, so the {len(locked_rows)} `--locked` rows are the " f"ones that measure preservation; {locked_ok} of them exited 0. The " - "[machine-readable results](uv-compatibility/results.json) contain all " + "machine-readable results JSON contains all " f"{len(all_obs)} observations and their command definitions. The " - "[binary catalog](uv-compatibility/binaries.json) records each uv wheel's " + "binary catalog records each uv wheel's " "public PyPI source and verified hash." ) paragraph(