Skip to content

Commit 212c825

Browse files
leliaclaude
andcommitted
fix(gitlab): separate namespace and name with a slash, not a colon
Reverts the separator introduced two commits ago. It rested on a report that the slash form does not resolve, which has since failed to reproduce: every affected link in that report loads, and the report's own screenshots show a working slash-form link. The defect those links actually exhibit is a namespace and name fused with no separator at all, which yields one path segment that cannot be split back into two. A slash fixes that and matches what the other package construction path has always emitted. The missing-namespace warning is kept and re-aimed: an absent namespace is what produces the unsplittable single segment, so that is the case worth surfacing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent ff7ae5a commit 212c825

3 files changed

Lines changed: 18 additions & 26 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@
66

77
- Full-scan package identities and Socket links now preserve namespaced packages
88
when the SDK returns enum-backed ecosystem values.
9-
- Maven package links use the `groupId:artifactId` form the Socket dashboard
10-
expects. The slash-separated form returned a 404 for every Maven package, on
11-
both the full-scan and diff code paths. Purl strings are unchanged and keep the
12-
slash form the purl spec defines.
9+
- Namespaced package links separate the namespace from the name instead of
10+
concatenating them, so Maven links no longer fuse groupId and artifactId into a
11+
single unresolvable path segment. A namespaced package whose namespace is
12+
missing now logs a warning rather than emitting a broken link silently.
1313
- GitLab dependency-scanning reports emit CVE and GHSA identifiers from current
1414
API fields while remaining compatible with legacy CVE data.
1515
- Implicit diff baselines are selected from the same workspace, scan type,

‎socketsecurity/core/classes.py‎

Lines changed: 9 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -14,13 +14,10 @@
1414

1515
log = logging.getLogger("socketdev")
1616

17-
# Separator between namespace and name in a socket.dev package URL. Socket addresses
18-
# Maven artifacts as "groupId:artifactId" -- the slash form 404s, and the dashboard's
19-
# Maven handler raises "Maven package must have a colon" on it. Every other ecosystem
20-
# uses a path segment per component (npm "@scope/name", golang "github.com/org/repo").
21-
URL_NAMESPACE_SEPARATORS = {
22-
"maven": ":",
23-
}
17+
# Ecosystems whose package pages cannot be addressed by name alone. A Maven
18+
# coordinate is a groupId plus an artifactId; with no namespace the URL collapses to
19+
# one path segment that cannot be split back into two, and the page does not resolve.
20+
NAMESPACE_REQUIRED_TYPES = frozenset({"maven"})
2421

2522
__all__ = [
2623
"Report",
@@ -168,8 +165,7 @@ def socket_url(package_type, namespace: Optional[str], name: str, version: str)
168165
"""
169166
Builds the socket.dev package overview URL for a package.
170167
171-
The namespace separator is ecosystem-dependent; see URL_NAMESPACE_SEPARATORS.
172-
Purl strings are not, and keep the "/" form everywhere.
168+
Namespace and name are separate path segments, the same form purl strings use.
173169
174170
Args:
175171
package_type: Ecosystem, as a string or SocketPURL_Type member
@@ -182,17 +178,13 @@ def socket_url(package_type, namespace: Optional[str], name: str, version: str)
182178
"""
183179
package_type = Package.normalize_type(package_type)
184180
namespace = (namespace or "").strip("/")
185-
separator = URL_NAMESPACE_SEPARATORS.get(package_type, "/")
186-
if separator != "/" and not namespace:
187-
# An ecosystem with its own separator cannot be addressed without the
188-
# namespace half of the coordinate. The link is emitted anyway so the
189-
# finding still reports, but it will not resolve.
181+
if not namespace and package_type in NAMESPACE_REQUIRED_TYPES:
182+
# The link is still emitted so the finding reports, but it cannot resolve.
190183
log.warning(
191184
f"{package_type} package {name}@{version} has no namespace, so its "
192-
f"Socket link cannot use the '{separator}' separator the dashboard "
193-
"requires and will not resolve"
185+
"Socket link collapses to a single path segment and will not resolve"
194186
)
195-
package_path = f"{namespace}{separator}{name}" if namespace else name
187+
package_path = "/".join(part for part in (namespace, name) if part)
196188
return f"https://socket.dev/{package_type}/package/{package_path}/overview/{version}"
197189

198190
@classmethod

‎tests/core/test_package_and_alerts.py‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -123,11 +123,11 @@ def test_full_scan_package_normalizes_enum_type_and_namespace_url(self):
123123
assert package.type == "maven"
124124
assert package.purl == "maven/com.example/example-core@1.2.3"
125125
assert package.url == (
126-
"https://socket.dev/maven/package/com.example:example-core/overview/1.2.3"
126+
"https://socket.dev/maven/package/com.example/example-core/overview/1.2.3"
127127
)
128128

129-
def test_maven_package_url_uses_colon_between_group_and_artifact(self):
130-
"""Socket addresses Maven artifacts as groupId:artifactId; the slash form 404s"""
129+
def test_maven_package_url_separates_group_and_artifact(self):
130+
"""groupId and artifactId are distinct path segments, not one fused string"""
131131
artifact = SocketArtifact.from_dict({
132132
"id": "pkg:maven/org.apache.logging.log4j/log4j-api@2.17.2",
133133
"type": "maven",
@@ -143,7 +143,7 @@ def test_maven_package_url_uses_colon_between_group_and_artifact(self):
143143
package = Package.from_socket_artifact(asdict(artifact))
144144

145145
assert package.url == (
146-
"https://socket.dev/maven/package/org.apache.logging.log4j:log4j-api"
146+
"https://socket.dev/maven/package/org.apache.logging.log4j/log4j-api"
147147
"/overview/2.17.2"
148148
)
149149
# The purl keeps the "/" form, which is what the purl spec and the purl API want.
@@ -189,7 +189,7 @@ def test_diff_path_builds_the_same_maven_url_as_the_full_scan_path(self):
189189
package = Core.update_package_values(package)
190190

191191
assert package.url == (
192-
"https://socket.dev/maven/package/com.google.code.gson:gson/overview/2.8.6"
192+
"https://socket.dev/maven/package/com.google.code.gson/gson/overview/2.8.6"
193193
)
194194

195195
def test_create_packages_dict_with_transitives(self, core):

0 commit comments

Comments
 (0)