Repository navigation
Commit dfa7f42
* Revert a vendored npm/Bun package after upgrade
Moving a vendored package to another version (`npm install pkg@x`,
`bun update`, a Dependabot bump) left the vendored copy and its ledger
entry stuck. `scan --prune`, `vendor --revert`, `remove` and `rollback`
called the moved lock entry "drift" and kept everything, so
`vendor --check` stayed red and every remedy it named looped.
A lock entry that now locks a different version than the one vendored
means the vendored version left the lock graph, the same as after
`npm uninstall`. The npm and Bun text-lock reverts now report it as
`vendor_lock_entry_removed`, leave the user's lock untouched, and
delete the artifact once no lock resolves through it. A re-resolution
at the same version is still drift and still keeps the artifact.
Fixes #1155
Assisted-by: Claude Code:claude-opus-5-5
* Test scan --prune after a vendored npm upgrade
Covers the `scan --prune` leg of #1155 end to end: after
`npm install left-pad@1.3.1` over a vendored 1.3.0, one prune run
reverts the entry, removes the artifact and leaves the user's lock
byte-identical.
Assisted-by: Claude Code:claude-opus-5-5
* Only treat same-registry version moves as upgrades
A lock entry that kept the vendored key but changed its version was
reverted as an upgrade no matter where it resolved. An edited lock could
point that entry at any tarball, and `scan --prune`, `remove` or
`rollback` would then delete the vendored copy and turn
`vendor --check` green.
An upgrade now has to be the same package from the registry the
pre-vendor entry used: for npm the new `resolved` must share the
original's `<registry>/<name>/-/` tarball directory, and for Bun the
spec's package name and the tuple's registry field must match. Anything
else stays drift, keeps the artifact and leaves `vendor --check` red.
Assisted-by: Claude Code:claude-opus-5-5
* Accept http-to-https registry upgrades
Older npm locks record `http://` registry tarball URLs, and the next
`npm install` rewrites them to `https://`. An upgrade made that way
was still called drift, so the vendored copy stayed stuck as in
#1155. A move from `http` to `https` on the same registry now counts
as an upgrade; a move from `https` down to `http` stays drift.
Assisted-by: Claude Code:claude-opus-5-5
* Require the exact tarball name for upgrades
An upgraded npm entry was accepted when its `resolved` sat under the
recorded registry directory and ended in `.tgz`. A URL written with
backslashes or `..` passed that check, but npm normalizes it before
fetching, so it could point at another package's tarball while the
vendored copy was deleted. The tarball file must now be exactly
`<name>-<version>.tgz`, with the name taken from the pre-vendor tarball
and a plain version; anything else stays drift.
Assisted-by: Claude Code:claude-opus-5-5
* Read legacy npm alias versions on upgrade
Lockfile v1 alias rows store their version as `npm:left-pad@1.3.0`,
so the new exact tarball-name check never matched them and a real
alias upgrade was still kept as drift. The tarball version is now
read from after the last `@` of an `npm:` spec before the same strict
check runs.
Assisted-by: Claude Code:claude-opus-5-5
* Keep non-registry installs out of upgrades
An entry npm installs from a git, URL or `file:` spec could still be
read as a registry upgrade when its lock `resolved` was written in the
registry tarball shape. npm ci installs such an edge from the spec, so
the revert deleted the vendored copy while something else got
installed. The revert now reads the same non-registry edge set the
vendor scan uses (including a registry override's rescue, #490) and
keeps any such entry as drift.
Assisted-by: Claude Code:claude-opus-5-5
* Distrust upgrades a project config can redirect
Two more ways an edited project could make the revert delete a
vendored copy while something else gets installed:
- npm: a package.json override can swap a registry edge for a git, URL
or file: spec, which npm ci installs instead of the lock's resolved
tarball. While any override names the vendored package, a version
change now stays drift.
- Bun: an empty registry field means the default registry, which a
committed bunfig.toml or .npmrc can rebind. When either file names a
registry, an upgrade from the default registry now stays drift.
Both fall back to the pre-#1155 behavior, which keeps the vendored
copy, whenever the project's own config could change the install
source.
Assisted-by: Claude Code:claude-opus-5-5
* Trust upgrades only without redirecting config
Review found more ways committed project config can change where an
"upgraded" package installs from, while the revert deletes the
vendored copy: a project .npmrc registry or replace-registry-host
rewrites npmjs dist URLs at fetch time, a Bun [install.scopes] table
rebinds a scope, and an npm override keyed on an alias edge swaps its
source.
Instead of matching each spelling, the upgrade shortcut now applies
only when the project has no such config at all: no `overrides` in
package.json, and no .npmrc or bunfig.toml that mentions a registry or
a scope (or can't be read). Otherwise the revert drift-keeps exactly
as before #1155.
Assisted-by: Claude Code:claude-opus-5-5
* Fail closed on any project or env registry config
The upgrade shortcut skipped a project .npmrc that only set a proxy,
`strict-ssl=false` or a CA file, since it looked for the words
"registry" and "scope". Those settings can also change what npm
fetches. Any setting at all in the project .npmrc or bunfig.toml, or a
`NPM_CONFIG_REGISTRY` / `npm_config_registry` / `BUN_CONFIG_REGISTRY`
in the environment, now keeps a version move as drift. A file of only
comments or blank lines still counts as no config.
Assisted-by: Claude Code:claude-opus-5-5
* Fix the build after merging main's bun.lockb rework
#1147 landed a bun.lockb revert that calls bun_lock::revert_one_record
for a migrated text record, and main moved npm_lock's npm_origin
import. Both broke against this branch in the merge queue (clippy:
E0061, E0425). Pass `false` for the new default-registry argument from
the bun.lockb path, which keeps a moved default-registry tuple there as
drift: bun.lockb stays outside the #1155 upgrade path. Import
legacy_packages_key again.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mo7HM9gyRkUAMxWqi62Dxz
* Repin live minimist@1.2.2 suites to republished patch 642d7f02
Port of #1301 (fixes #1293). Production withdrew the free
minimist@1.2.2 patch 80630680 and republished the fix as 642d7f02,
which turned hosted-e2e, e2e_safety_pnpm and every Bun native leg red
here as on main. The vlt harness also now reads the republished
patch's unprefixed file keys. Test-only; a no-op once main carries
#1301.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mo7HM9gyRkUAMxWqi62Dxz
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 2677eda commit dfa7f42
7 files changed
Lines changed: 993 additions & 4 deletions
File tree
- crates
- socket-patch-cli/tests
- socket-patch-core/src/vendor
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
543 | 543 | | |
544 | 544 | | |
545 | 545 | | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
| 627 | + | |
546 | 628 | | |
547 | 629 | | |
548 | 630 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1161 | 1161 | | |
1162 | 1162 | | |
1163 | 1163 | | |
| 1164 | + | |
| 1165 | + | |
| 1166 | + | |
| 1167 | + | |
| 1168 | + | |
| 1169 | + | |
| 1170 | + | |
| 1171 | + | |
| 1172 | + | |
| 1173 | + | |
| 1174 | + | |
| 1175 | + | |
| 1176 | + | |
| 1177 | + | |
| 1178 | + | |
| 1179 | + | |
| 1180 | + | |
| 1181 | + | |
| 1182 | + | |
| 1183 | + | |
| 1184 | + | |
| 1185 | + | |
| 1186 | + | |
| 1187 | + | |
| 1188 | + | |
| 1189 | + | |
| 1190 | + | |
| 1191 | + | |
| 1192 | + | |
| 1193 | + | |
| 1194 | + | |
| 1195 | + | |
| 1196 | + | |
| 1197 | + | |
| 1198 | + | |
| 1199 | + | |
| 1200 | + | |
| 1201 | + | |
| 1202 | + | |
| 1203 | + | |
| 1204 | + | |
| 1205 | + | |
| 1206 | + | |
| 1207 | + | |
| 1208 | + | |
| 1209 | + | |
| 1210 | + | |
| 1211 | + | |
| 1212 | + | |
| 1213 | + | |
| 1214 | + | |
| 1215 | + | |
| 1216 | + | |
| 1217 | + | |
| 1218 | + | |
| 1219 | + | |
| 1220 | + | |
| 1221 | + | |
| 1222 | + | |
| 1223 | + | |
| 1224 | + | |
| 1225 | + | |
| 1226 | + | |
| 1227 | + | |
| 1228 | + | |
| 1229 | + | |
| 1230 | + | |
| 1231 | + | |
| 1232 | + | |
| 1233 | + | |
| 1234 | + | |
| 1235 | + | |
| 1236 | + | |
| 1237 | + | |
| 1238 | + | |
| 1239 | + | |
| 1240 | + | |
| 1241 | + | |
| 1242 | + | |
| 1243 | + | |
| 1244 | + | |
| 1245 | + | |
| 1246 | + | |
| 1247 | + | |
| 1248 | + | |
| 1249 | + | |
| 1250 | + | |
| 1251 | + | |
| 1252 | + | |
| 1253 | + | |
| 1254 | + | |
1164 | 1255 | | |
1165 | 1256 | | |
1166 | 1257 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
644 | 644 | | |
645 | 645 | | |
646 | 646 | | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
647 | 650 | | |
648 | 651 | | |
649 | 652 | | |
650 | 653 | | |
| 654 | + | |
651 | 655 | | |
652 | 656 | | |
653 | 657 | | |
| |||
0 commit comments