You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The previous wording told users to restore the pre-vendor lockfile
and prune again. That lock has no .socket/vendor paths, so the prune
would revert every vendored entry, not just the stale ones.
The warning now names only scan --prune. A prune that drift-keeps an
entry already explains it on its own GC: kept line, so the warning
points there instead of suggesting a lock edit whose reach it cannot
bound.
Assisted-by: Claude Code:claude-opus-5-5
Copy file name to clipboardExpand all lines: crates/socket-patch-cli/CLI_CONTRACT.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1149,7 +1149,7 @@ Every `--json` invocation emits a single JSON object that follows the **unified
1149
1149
|`reinstall_required`| rollback `warnings[]`| rollback (v5.0): vendored/hosted wiring was unwound, but installed trees keep their patched bytes until the next package-manager install — the stale-install advisory. |
1150
1150
|`hosted_state_not_preservable`| rollback `warnings[]`| rollback `--preserve-state` (v5.0): hosted pins were restored to upstream anyway — the lockfile pins are hosted mode's only record, so there is no local state to preserve; re-run `scan --mode hosted` to re-wire. (`remove --preserve-state` prints the same note on stderr.) |
1151
1151
|`out_of_scope_copies_restored`| rollback `warnings[]`| path-scoped rollback (v5.0): a selected patch had installed copies outside the given patterns; ALL copies were restored (patches are per-package). Informational — never flips the exit. |
1152
-
|`vendor_ledger_entry_unwired`| scan `warnings[]`| a vendored entry's dependency left the lockfile (upgraded or removed), so the ledger supplement skipped it; the detail names the purls and points at `scan --prune`, which reverts them (no warning on a pruning non-hosted run). For an entry that prune drift-keeps because its lock entries were re-resolved since vendoring, it names the convergent way out: restore the lockfile from before vendoring, `scan --prune` again (the reverts then converge), and re-run the package manager's install. |
1152
+
|`vendor_ledger_entry_unwired`| scan `warnings[]`| a vendored entry's dependency left the lockfile (upgraded or removed), so the ledger supplement skipped it; the detail names the purls and points at `scan --prune`, which reverts them (no warning on a pruning non-hosted run). An entry that prune drift-keeps (its lock entries were re-resolved since vendoring, e.g. an npm uninstall re-locked it away) is reported on the prune's `GC: kept` line and keeps being warned about. |
1153
1153
|`path_scope_excluded_supplements`| scan `warnings[]`| path-scoped scan (v5.0): lockfile-only / vendor-ledger supplement packages have no installed path and were excluded from the scoped scan; the detail carries the count. |
1154
1154
|`vendor_commit_failed`| top-level error (`vendor`, and the nested vendor envelope of `scan` / `get --mode vendored`) | v5.0 group commit: the run's lockfile / manifest / ledger edits could not be written (the detail names the I/O error). Exit 1; the project's lockfiles and `.socket/vendor/state.json` are left as they were before the run (a partially-applied commit is put back), and the per-package events describe the uncommitted outcome. When putting a partially-applied commit back fails too, the journal is kept instead and the detail says the next socket-patch command in the project finishes the commit. |
1155
1155
|`vendor_state_unreadable`| rollback `warnings[]`; remove top-level error | corrupt-ledger containment (v5.0). Rollback: an unreadable vendor ledger skips the vendored leg + manifest cleanup + GC and drives `partial_failure` exit 1 while the agent and hosted legs still run. Remove: a hard top-level error before any mutation. Also the Bun vendored preflight's refusal code: `get` / `scan --mode vendored`, `vendor`'s pre-takeover check and the `--dry-run``would_refuse` preview report an unreadable `.socket/vendor/state.json` as itself (`errorCode` in `patches[]` / `download.patches[]`, or `get <uuid>`'s top-level `error.code`), fail-closed — nothing is exempt — instead of a Bun lock code. (v4's `redirect_state_unreadable` is no longer emitted: v5 never reads the redirect ledger on these paths.) |
0 commit comments