Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 33 additions & 7 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,33 @@ into the new version's section — see docs/releasing.md.
`gem_setup` / `composer_setup` / `pth_hook` aliases are removed from
`socket-patch-core`, along with the setup-only `npm_family` table column
(`FileRow::detects_pnpm`) and `VLT_SETUP_MARKERS`.
- **v3/v4 compatibility spellings are gone.**
- The v3.0 legacy env names `SOCKET_PATCH_PROXY_URL`, `SOCKET_PATCH_DEBUG`
and `SOCKET_PATCH_TELEMETRY_DISABLED` are no longer read and no longer
print a deprecation warning. Use `SOCKET_PROXY_URL`, `SOCKET_DEBUG` and
`SOCKET_TELEMETRY_DISABLED`.
- The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden
no-op `scan --detached` flag (vendored mode is always manifest-free) are
removed. Both are now unknown-flag usage errors (exit 2).
- The hidden `--mode` values `host`, `redirect` and `vendor` on `scan` and
`get` are rejected; only `hosted`, `vendored` and `agent` are accepted.
The hidden `scan --apply` and `scan --vendor` spellings stay.
- **`get --one-off` and `rollback --one-off`** (and `SOCKET_ONE_OFF`) are
removed. They were never implemented and only failed with a usage error;
`--one-off` is now an unknown-flag error (still exit 2) and
`SOCKET_ONE_OFF` is ignored.
- **`.socket/packages/` package archives are no longer read.** Nothing has
written them for several releases. `apply`, `vendor` and `repair` stop
probing and staging the directory, and `apply`'s JSON `appliedVia` loses
its `"package"` value (`"diff"` or `"blob"` remain). The GC sweeps
(`scan --prune`, `rollback`, `remove`, `repair`) delete any leftover
`.socket/packages/` files whole (`rollback` and `scan --prune` still
report them as `removedPackageArchives`).
- **Core crate:** removed uncalled public helpers
(`bun_lock::snapshot_binary_workspace_artifacts`, `vlt_lock_sniff_ok`,
and several `lock_inventory::view` accessors) and the never-read
`DepOverride::berry_zip_url` field (a `berryZipUrl` key in a patch
reference still parses).

### Changed (BREAKING): patch UI streamlining

Expand All @@ -96,10 +123,10 @@ into the new version's section — see docs/releasing.md.
confirmation, in `--json` too (no `selection_required` outside agent
mode). Agent-mode `get` keeps its picker and `Download and apply N
patches?` prompt.
- **`get` and `rollback` usage errors exit 2** (were 1): `get`'s
`--id`/`--cve`/`--ghsa`/`--package` multi-select, `--one-off --save-only`,
`--mode hosted|vendored --save-only`, `--one-off`, a malformed forced
identifier, and `rollback --one-off`. Every usage error now exits 2.
- **`get` usage errors exit 2** (were 1): `get`'s
`--id`/`--cve`/`--ghsa`/`--package` multi-select,
`--mode hosted|vendored --save-only` and a malformed forced identifier.
Every usage error now exits 2.
- **Human output:** warning lines no longer carry the `(code)` tag
(`Warning: …`, `GC: skipped: …`); the codes stay in the JSON envelope.
Error lines keep theirs (`Error (<code>): …`). Hosted mode is called "hosted", not "redirect", in human
Expand Down Expand Up @@ -502,9 +529,8 @@ into the new version's section — see docs/releasing.md.
selected patch records are fetched into memory and every vendor-ledger entry
carries `detached: true` plus the embedded `record` as its verification
source, so a vendored project's footprint is `.socket/vendor/**` only. The
former `--detached` opt-in is now the only vendored posture — the flag is
hidden, accepted as a no-op for compatibility, and still a usage error
without vendored mode. JSON uses the detached download vocabulary for both
former `--detached` opt-in is now the only vendored posture, and the flag
itself is removed (see "Removed"). JSON uses the detached download vocabulary for both
commands (`downloaded: N`, `detached: true`, `patches[].action` =
`downloaded` | `skipped` | `failed`). The vendor step vendors exactly what
discovery selected — the "whole manifest is vendored" re-vendor from a
Expand Down
7 changes: 2 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -644,16 +644,15 @@ socket-patch scan [PATHS]... [options]
|------|---------|-------------|
| `--mode <hosted\|vendored\|agent>` | — | Selects one of the three [patch modes](#three-patch-modes) (default: `hosted`). Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. |
| `--package <name\|purl>` | `SOCKET_SCAN_PACKAGES` | Only scan these packages: a name (`lodash`, `@scope/pkg`, `requests`; case-insensitive) or a purl with or without its version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`). Repeat the flag or separate with commas. |
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff/package-archive files. [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff-archive files (plus any legacy package archives). [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
| `--sync` | — | Shorthand for `--mode agent --prune`: the one-flag agent-mode auto-update run. |
| `--batch-size <n>` | `SOCKET_BATCH_SIZE` | Packages per API request (default: `500` on the authenticated API, `100` on the public proxy). A request whose body would exceed 256 KiB is split into smaller ones. |
| `--all-releases` | `SOCKET_ALL_RELEASES` | Store patches for every release/distribution variant, not just the installed one — PyPI wheel/sdist, RubyGems platform, Maven classifier. Makes the manifest portable across environments (e.g. cross-platform CI caches). |
| `--vex <path>` | `SOCKET_VEX` | On a successful scan, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX](#inline-vex-on-apply--scan--vendor). |
| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. |

> Deprecated, hidden spellings (still accepted): `--apply` (== `--mode agent`) and
> `--vendor` (== `--mode vendored`). `--detached` is a hidden no-op kept for compatibility (vendored mode is
> always manifest-free); it is still an error without vendored mode.
> `--vendor` (== `--mode vendored`).

**Examples:**
```bash
Expand Down Expand Up @@ -901,7 +900,6 @@ socket-patch get <identifier> [options]
| `--ghsa` | — | Force identifier to be treated as a GHSA ID. |
| `-p, --package` | — | Force identifier to be treated as a package name. |
| `--save-only` | `SOCKET_SAVE_ONLY` | Download the patch without applying it (alias: `--no-apply`). |
| `--one-off` | `SOCKET_ONE_OFF` | Reserved (hidden from `--help`): apply the patch immediately without saving to the `.socket` folder. **Not yet implemented** — the command currently errors up front. |
| `--all-releases` | `SOCKET_ALL_RELEASES` | Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. |
| `--mode <hosted\|vendored\|agent>` | — | How to consume the patch; the same modes as `scan --mode` (default: `agent`). |

Expand Down Expand Up @@ -1020,7 +1018,6 @@ socket-patch rollback [targets]... [options]
| Flag | Env var | Description |
|------|---------|-------------|
| `--preserve-state` | `SOCKET_PRESERVE_STATE` | Unpatch the system but keep the local patch state — manifest entries, vendored artifacts + ledger entries — for a later re-apply, and skip GC. Hosted patches have no preservable state (the lockfile is their only record) and are restored to upstream either way. |
| `--one-off` | `SOCKET_ONE_OFF` | Reserved: rollback by fetching original (`beforeHash`) files from the API, no manifest required. **Not yet implemented** — the command currently errors up front. |

**Examples:**
```bash
Expand Down
Loading
Loading