Skip to content

Fix report-only scan -g hint dropping -g (#464) - #777

Open
Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
mainfrom
agent/fix-report-only-hint-global-scope
Open

Mikola Lysenko (mikolalysenko) wants to merge 2 commits into
mainfrom
agent/fix-report-only-hint-global-scope

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #464

Summary

scan -g and scan --global-prefix <dir> with no --mode only report. They end with a hint showing how to apply what they found. The hint used to drop the global scope:

To apply these patches in place, run:
  socket-patch scan --mode agent [PATHS]
  socket-patch get <package-name-or-purl-or-CVE-ID>

If you ran it as printed, it scanned the cwd project instead of the global install, exited 0, and left the global copy unpatched. The hint now repeats the run's scope:

  socket-patch scan --mode agent -g
  socket-patch get -g <package-name-or-purl-or-CVE-ID>

With a prefix, it prints --global-prefix '<dir>' instead, shell-quoted only when the path needs it (POSIX single quotes; double quotes on Windows). A project --prune report-only scan keeps the old hint.

Root cause

render::report_only_hint() took no arguments, so it never saw the run's GlobalArgs. It now takes &GlobalArgs and builds both commands from global / global_prefix. SOCKET_GLOBAL / SOCKET_GLOBAL_PREFIX set the same fields, so they're covered too. CLI_CONTRACT.md documents the scoped hint.

The npm, PyPI and gem wrappers only dispatch to the binary, so they need no change.

Tests (red → green)

Issue Test Without the fix With the fix
#464 (-g, --global-prefix, quoting) scan::render::tests::report_only_hint_keeps_global_scope (unit) does not compile (the hint takes no scope) pass
#464 (real report-only scan) covgap_commands_scan_mod::scan_global_report_only_hint_keeps_the_global_scope fails: the hint printed socket-patch scan --mode agent [PATHS] pass
project hint unchanged report_only_hint_names_agent_mode, scan_prune_without_a_mode_is_report_only pass pass

Commands run locally on b311073:

  • cargo clippy --workspace --all-features -- -D warnings: clean.
  • cargo test -p socket-patch-cli --all-features --lib: 835 passed.
  • cargo test -p socket-patch-cli --all-features --test covgap_commands_scan_mod --test cli_parse_scan --test e2e_socket_yml_policy: 45 + 52 + 20 passed.
  • cargo fmt --check: my hunks are clean. main already has about 500 rustfmt diffs under the pinned 1.93.1 toolchain, and CI doesn't run fmt, so I didn't reformat unrelated code.
  • A full cargo test --workspace filled the sandbox disk while linking test binaries, so the full suite is left to CI.

🤖 Generated with Claude Code


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
A report-only `scan -g` (or `--global-prefix <dir>`) ends with a hint
for applying what it found. The hint dropped the global flag, so
running it as printed scanned the cwd project instead, exited 0, and
left the global install unpatched.

The hint now repeats the run's scope: `-g`, or `--global-prefix <dir>`
shell-quoted when the path needs it. A project `--prune` scan keeps
the old hint. Covered by unit tests on the hint and an integration
test of a real report-only global-prefix scan.

Fixes #464

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 4, 2026 12:48
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit b311073. Configure here.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] Ready for review at b311073.


Generated by Claude Code

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

2 participants