You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b194fa1
Browse filesBrowse the repository at this point in the historyBrowse files
* Start fix for #725
Assisted-by: Claude Code:claude-opus-5-5
* Fail vendor --check when lock drops vendored ref
`vendor --check` only verified wiring for Maven/Gradle entries. For
every other ecosystem it reported "committed artifact and wiring
verified" and exited 0 even after `pipenv lock`, `uv lock`,
`npm install` or a hand edit pointed the lockfile back at the
registry, so a CI gate stayed green while fresh installs got the
unpatched package and `vex` refused the same checkout.
Each non-JVM entry is now judged by the same vendor-ledger liveness
rule `vex` and `scan` use; an unwired entry fails with
`vendor_check_failed` and exit 1. Regression tests cover Pipenv,
requirements.txt, Poetry, uv, Hatch and npm.
Fixes#725
Assisted-by: Claude Code:claude-opus-5-5
* Run npm wiring check before generic liveness in vendor --check
The npm package-lock check (#589) names the exact unwired lock entry;
running the generic liveness rule first replaced that reason, failing
e2e_vex_vendor after merging main.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01519c1ZV6MhuxyVisVJ5FYz
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: mikolalysenko <mik@socket.dev>
// A relock (`pipenv lock`, `npm install`, `uv lock`, …) can
1009
+
// drop the `.socket/vendor/` reference while the artifact stays
1010
+
// intact; a fresh install is then unpatched. Same rule as
1011
+
// `vex`'s `vendor_unwired`.
1012
+
if !discovery.vendor_entry_live(root, entry).await{
1013
+
failure = Some(format!(
1014
+
"wiring missing: no lockfile or config references .socket/vendor/{}/{} any more, so a fresh install gets the unpatched package; re-run `socket-patch vendor` to rewire it",
1015
+
entry.ecosystem, entry.uuid
1016
+
));
1017
+
}
1018
+
}
990
1019
if vendor::jvm::apply::upstream_unverified(entry){
991
1020
env.warnings.push(RunWarning{code:"vendor_jvm_upstream_unverified".into(),detail:format!("{key}: upstream metadata was accepted offline; run vendor online to verify registry checksums")});
0 commit comments