Keep NuGet patches installed with <clear /> and NuGet.config - #284
Conversation
Hosted mode inserted the Socket package source (and, when the config already had a packageSourceMapping, its mapping) directly after the section's open tag. A config that starts the section with <clear />, common in corporate setups, then discarded the Socket entry, so dotnet restore failed NU1100 / NU1101 for the patched package. The entries now land after the last <clear /> in their section. Assisted-by: claude-code:claude-opus-5-5
NuGet reads the first of nuget.config, NuGet.config and NuGet.Config in a directory. Hosted mode only read nuget.config and vendored mode skipped NuGet.config, so on a case-sensitive filesystem a project whose config used another spelling got a new nuget.config that shadowed it. Its sources and mappings were ignored and packages from private feeds failed to restore. Both modes now edit the existing file in place and only create nuget.config when no spelling exists. Assisted-by: claude-code:claude-opus-5-5
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 375681d. Configure here.
… inserts The after-<clear /> insert found section bounds with literal `</packageSources>` / `</packageSourceMapping>` and the mapping open tag with a literal `<packageSourceMapping>`. A close tag with whitespace before `>` sent the insert back ahead of the `<clear />`, which drops it; a spaced mapping open tag authored a duplicate section. A commented-out `<clear />` also became the anchor, splicing the Socket source inside the comment. Match tags with the same whitespace/attribute tolerance as the rest of the rewriter and skip comments. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NPYQfCTLY7F4eQTa8hjinL
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NPYQfCTLY7F4eQTa8hjinL
|
Generated by Claude Code |
f6b7fb9
into
main
|
Summary of the follow-up work on this PR. It was merged at 12:00 UTC. Review comments
Found in my own review
Commits
CI on 02ee0a6
Still open
Generated by Claude Code |

LLM Description written by Claude Code:claude-opus-5-5
Hosted and vendored NuGet patches now install on projects whose
nuget.configstarts a section with<clear />, and on projects whose config file is spelledNuGet.configorNuGet.Config. Before this,dotnet restorefailed with NU1100 or NU1101 in both cases. The work came out of the depscan NuGet patch SBOM annotation effort; its depscan PRs follow.<clear />dropped the Socket source (hosted)Hosted mode inserted the Socket package source right after the
<packageSources>open tag. When the config already had a mapping section, it inserted the Socket mapping right after<packageSourceMapping>too. A<clear />at the top of either section, which is common in corporate configs, then threw the Socket entry away:<clear />in<packageSources>failed restore withNU1100, reproduced on SDK 6.0, 8.0 and 10.0;<clear />in<packageSourceMapping>failed withNU1101.Both entries now go after the last
<clear />in their section. Vendored mode already appended after existing entries, so it wasn't affected.Config spelling shadowed the user's config (hosted and vendored)
NuGet reads only the first of
nuget.config,NuGet.configandNuGet.Configin a directory; this was confirmed with real SDKs.nuget.config. With a project config namedNuGet.config, it created a newnuget.confignext to it. That hid the project's private feed, and restore failed withNU1101.nuget.configand thenNuGet.Config, so it missedNuGet.configthe same way.Both modes now edit whichever spelling exists, and create
nuget.configonly when none does. The in-memory hosted engine (hosted_memory/roots.rs,redirect.rs) andscan/hosted.rspick up the same candidate list.Tests
patch/redirect/mod.rsandvendor/nuget_feed.rs, plus an in-processget --mode hostedtest inin_process_get_hosted_ecosystems.rs. Each fails without its fix.cargo test -p socket-patch-core --lib nugetpasses (186 tests), and so doescargo test -p socket-patch-cli --test in_process_get_hosted_ecosystems nuget. The broader core and CLI suites ande2e_vex_lockfilealso passed, as did the CI clippy command.dotnet restore.NuGet.configgap is covered only by the unit test.Failures already on
mainthat this PR does not touch:vlt_healtest fails when run as root;--all-targetsclippy fails oncovgap_commands_rollback.rs, which CI doesn't lint;cargo fmt --checkfails across about 60 files, and CI has no fmt step.Only the changed lines are formatted, to keep the diff small next to other work in
redirect/mod.rsandvendor/.🤖 Generated with Claude Code
Note
Medium Risk
Changes NuGet config rewrite semantics for hosted and vendored flows; mistakes could break
dotnet restorefor corporate configs, but behavior is narrowly scoped with targeted regression tests.Overview
Fixes two NuGet restore failures in hosted redirects and vendored wiring that showed up as NU1100 / NU1101 after patching.
<clear />innuget.config: Socket package sources andpackageSourceMappingentries were inserted at the top of<packageSources>/<packageSourceMapping>, so NuGet discarded them when a corporate config started the section with<clear />. Inserts now go after the last<clear />in that section vianuget_after_last_clear.Config filename casing: NuGet reads the first of
nuget.config,NuGet.config, andNuGet.Config. Hosted mode always wrotenuget.config; vendored mode skippedNuGet.config. On case-sensitive filesystems that shadowed the project’s real file and dropped private feeds. Both paths now shareNUGET_CONFIG_FILE_NAMESand edit whichever file is present (scan/hosted discovery lists all three spellings).Unit tests cover clear-tag placement and in-place rewrites; an in-process hosted
gettest and a vendored wiring test assert mixed-case configs stay intact without a shadow file.Reviewed by Cursor Bugbot for commit 375681d. Configure here.