Commit 2463257
feat!: consolidate the v5 patching workflow (#277)
Make scan and get use hosted patches by default, with live dependency files
as hosted state and upstream restoration for rollback and remove. Share
lockfile models, project snapshots and the hosted engine between disk and
in-memory workflows.
Use verified service artifacts and a shared backend for vendoring,
repair, rollback and removal. Support manifest-free vendored projects,
exact artifact reuse, release variants, Maven reactors and Gradle builds.
Add socket.yml rollout policy, package and severity filters, directory
targets and per-run limits on new patches. Rank patches by highest
severity, then most distinct advisories fixed, then publication date;
use the same policy for selection and upgrades.
Expand lockfile discovery, package-manager compatibility and OpenVEX
attestations. Reject multi-directory scans with a single VEX destination
before writes, and require TLS 1.2 in CI host-pin handshakes.
Remove setup, obsolete hooks and flags, and the PyPI/RubyGems CLI
distributions. Consolidate usage, migration and configuration docs,
simplify test suites, and run the full v5 compatibility tier on PRs.
Keep the version bump and release publication in the separate release
workflow.
Co-authored-by: Claude <noreply@anthropic.com>1 parent f6b7fb9 commit 2463257
793 files changed
Lines changed: 83448 additions & 237608 deletions
File tree
- .cargo
- .github
- actions/pin-socket-hosts
- workflows
- crates
- socket-patch-cli
- src
- commands
- scan
- hosted
- vendored_backend
- hosted_memory
- ui
- tests
- apply
- cli
- common
- docker_vendor_common
- e2e_vex_build
- e2e_vex_lockfile
- get
- hosted_memory_common
- in_process_redirect
- in_process_rollback_hosted
- in_process_vendor_bun_takeover
- in_process_vendor
- npm_e2e_common
- prebuilt_common
- remove
- repair_vendor_flavors_e2e
- repair
- rollback
- scan
- setup_matrix_common
- update
- vendor_ecosystem_fixtures
- vendor
- vex_e2e_common
- vex_pdm_hatch_common
- vex_pipenv_pip_common
- vex_pipenv_pip_real
- vex_pipenv_pip_steps
- vex_pypi_real_common
- vlt_e2e_common
- vlt_hosted_common
- vlt_vendor_common
- yarn_berry_common
- socket-patch-core
- src
- api
- crawlers
- formats
- bun
- cargo
- composer
- gem
- maven
- nuget
- pnpm
- yarn
- hosted
- memory
- manifest
- package_json
- patch
- redirect
- upstream
- sidecars
- policy
- rollout
- setup
- composer
- gem
- templates
- pypi
- update
- utils
- vendor
- composer_lock
- jvm
- lock_inventory
- test_support
- vex
- discover
- testing
- tests
- equivalence
- fixtures
- pipenv-shapes
- 2018.11.26
- extras
- marker-excluded
- 2022.12.19
- extras
- marker-excluded
- 2026.8.0
- extras
- marker-excluded
- redirect
- composer/composer-lock
- dist-mirrors-before-url/restored
- dist-mirrors/restored
- source-after-dist/restored
- source-before-name/restored
- source-last-key/restored
- source-not-adjacent/restored
- npm/vlt
- capture-1.2.0-config-registry
- expected
- input
- lock-v1-both-registry-keys
- input
- vex-discover-golden
- socket-patch-node
- npm
- test
- src
- docs
- design
- testing
- pdm-compatibility
- pipenv-compatibility
- poetry-compatibility
- uv-compatibility
- gem
- socket-patch-bundler
- socket-patch
- exe
- lib/socket_patch
- npm/socket-patch/src/schema
- pypi
- socket-patch-hook
- socket_patch_hook
- socket-patch
- socket_patch
- bin
- scripts
- perf
- tests
- tests
- docker
- fixtures/npm
- setup_matrix
- results
- shims
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
9 | 16 | | |
10 | 17 | | |
11 | 18 | | |
| |||
22 | 29 | | |
23 | 30 | | |
24 | 31 | | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
20 | 22 | | |
21 | 23 | | |
22 | 24 | | |
| |||
43 | 45 | | |
44 | 46 | | |
45 | 47 | | |
46 | | - | |
| 48 | + | |
47 | 49 | | |
48 | 50 | | |
49 | 51 | | |
50 | 52 | | |
51 | 53 | | |
52 | 54 | | |
53 | | - | |
| 55 | + | |
54 | 56 | | |
55 | 57 | | |
56 | 58 | | |
57 | 59 | | |
58 | 60 | | |
59 | 61 | | |
| 62 | + | |
| 63 | + | |
60 | 64 | | |
61 | 65 | | |
62 | 66 | | |
| |||
75 | 79 | | |
76 | 80 | | |
77 | 81 | | |
78 | | - | |
| 82 | + | |
79 | 83 | | |
80 | 84 | | |
81 | 85 | | |
| |||
95 | 99 | | |
96 | 100 | | |
97 | 101 | | |
98 | | - | |
99 | | - | |
| 102 | + | |
| 103 | + | |
100 | 104 | | |
101 | 105 | | |
102 | | - | |
| 106 | + | |
103 | 107 | | |
104 | 108 | | |
105 | 109 | | |
| |||
187 | 191 | | |
188 | 192 | | |
189 | 193 | | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
190 | 199 | | |
191 | 200 | | |
192 | 201 | | |
| |||
0 commit comments