Skip to content

Commit 9633810

Browse files
committed
Merge remote-tracking branch 'origin/main' into agent/fix-requirements-pep440-pin-match
2 parents bcc5335 + d63ae5f commit 9633810

101 files changed

Lines changed: 9580 additions & 642 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/ci.yml‎

Lines changed: 37 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -261,24 +261,47 @@ jobs:
261261
cache: false
262262

263263
- name: Install vexctl
264-
# `go install` puts the binary in $(go env GOPATH)/bin; surface
265-
# that path to subsequent steps so `Command::new("vexctl")` in
266-
# the test resolves. Pinned to a tagged release rather than
267-
# @latest for reproducibility.
264+
# Linux / Windows: the v0.3.0 release binary, checked against the
265+
# sha256 pinned here (from the release's vexctl_checksums.txt).
266+
# Compiling it took ~80s on ubuntu and ~180s on windows, the
267+
# slowest job in this workflow.
268268
#
269-
# Retried: the install compiles sigstore/cosign, whose module
270-
# verification reads dozens of sum.golang.org checksum tiles, and
271-
# transient INTERNAL_ERROR stream resets there have failed this
272-
# step on otherwise-green runs. The backoff rides out short
273-
# resets; a persistent outage still fails loudly on the last
274-
# attempt. Follow-up option if this recurs: install the pinned
275-
# release BINARY (sha256-pinned) instead of compiling, which
276-
# sidesteps module verification and drops ~100s of compile time per
277-
# leg.
269+
# macOS still compiles: the release's darwin binaries are built
270+
# with go1.22.7 and have no LC_UUID, so the runner's dyld refuses
271+
# them (see the Go step above). The compile is retried: it builds
272+
# sigstore/cosign, whose module verification reads dozens of
273+
# sum.golang.org checksum tiles, and transient INTERNAL_ERROR
274+
# stream resets there have failed this step on otherwise-green
275+
# runs. The backoff rides out short resets; a persistent outage
276+
# still fails loudly on the last attempt.
277+
#
278+
# Either way the binary's directory goes on PATH so
279+
# `Command::new("vexctl")` in the tests resolves.
278280
shell: bash
281+
env:
282+
VEXCTL_VERSION: v0.3.0
283+
VEXCTL_SHA256_LINUX_AMD64: cd7f8b57d20642166ed4eb3dd1fd849bbb30bbd7c5b9f5b0316b6003b57ceaba
284+
VEXCTL_SHA256_WINDOWS_AMD64: 346fb3104b656fe1a407cbae88ea29a636b36f4569ec58a5a8dadca7343993ed
279285
run: |
286+
set -euo pipefail
287+
case "$RUNNER_OS" in
288+
Linux) asset=vexctl-linux-amd64 bin=vexctl sha="$VEXCTL_SHA256_LINUX_AMD64" ;;
289+
Windows) asset=vexctl-windows-amd64.exe bin=vexctl.exe sha="$VEXCTL_SHA256_WINDOWS_AMD64" ;;
290+
*) asset='' ;;
291+
esac
292+
if [ -n "$asset" ]; then
293+
dir="$RUNNER_TEMP/vexctl-bin"
294+
mkdir -p "$dir"
295+
curl -fsSL --retry 5 --retry-all-errors -o "$dir/$bin" \
296+
"https://github.com/openvex/vexctl/releases/download/$VEXCTL_VERSION/$asset"
297+
echo "$sha $dir/$bin" | sha256sum -c -
298+
chmod +x "$dir/$bin"
299+
"$dir/$bin" version
300+
echo "$dir" >> "$GITHUB_PATH"
301+
exit 0
302+
fi
280303
for attempt in 1 2 3 4 5; do
281-
if go install github.com/openvex/vexctl@v0.3.0; then
304+
if go install "github.com/openvex/vexctl@$VEXCTL_VERSION"; then
282305
break
283306
fi
284307
if [ "$attempt" = 5 ]; then

‎CHANGELOG.md‎

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -102,6 +102,15 @@ limits, and required install commands.
102102

103103
### Fixed
104104

105+
- Agent-mode PyPI `apply` patches every installed copy of a release, not just
106+
the first one found. A Pipenv project with both a WORKON_HOME venv and a
107+
`./.venv`, or a global install with the same release in the user site and a
108+
system dir, no longer keeps the copy Python imports unpatched while `vex`
109+
attests it (#529, #501).
110+
- Gem hosted and vendored modes wire only the manifest Bundler loads. A `gems.rb`
111+
twin or a `BUNDLE_GEMFILE` setting (environment or `.bundle/config`) no longer
112+
leads to an edit of an ignored `Gemfile` that reports success and attests an
113+
unpatched gem; unsupported layouts are refused before any write (#341, #390).
105114
- **npm dependencies installed from git, a URL or `file:` are no longer
106115
reported patched.** npm installs such a dependency from the dependent's
107116
spec (`github:user/repo`, `https://…/x.tgz`, `file:…`) and ignores the
@@ -148,6 +157,9 @@ limits, and required install commands.
148157
- Python rewrites preserve supported markers, groups, extras, source metadata, and
149158
integrity pins. Relocks, out-of-tree environments, and lock-only VEX are handled
150159
consistently with each installer's supported behavior.
160+
- Hosted Pipenv scans read the `Pipfile`, so a conflicting `Pipfile.lock` entry
161+
refuses the patch project-wide instead of half-redirecting a sibling
162+
`requirements.txt` (#333).
151163
- Vendoring reuses valid committed artifacts during service outages. Updates do
152164
not build from a previous patch's modified bytes. Verified service artifacts
153165
keep their identity; integrity failures do not fall through to a local rebuild.
@@ -162,6 +174,27 @@ limits, and required install commands.
162174
- Transient apply locks are removed on normal command exit; no-op scans and full
163175
reversal avoid leaving unused `.socket/` state. Terminal output, telemetry
164176
timeouts, and update-check handling are more consistent.
177+
- Agent mode finds transitive npm packages in npm's linked store
178+
(`install-strategy=linked`, `node_modules/.store`) and in a relocated pnpm
179+
`virtualStoreDir`, instead of reporting them `package_not_installed` (#359,
180+
#362). A store outside the project, such as pnpm's global virtual store, is
181+
shared with other projects and is still not patched in place.
182+
- npm locks keep their own layout when edited. `scan --mode hosted`,
183+
`scan --mode vendored`, `rollback` and `vendor --revert`
184+
re-serialized `package-lock.json` / `npm-shrinkwrap.json` with LF line
185+
endings (and, in hosted mode, a fixed 2-space indent), so a CRLF or
186+
tab-indented lock got a whole-file diff and the undo did not restore its
187+
bytes. A lock with a UTF-8 BOM, which npm installs from, was skipped as
188+
unparseable (hosted) or refused as `vendor_lockfile_version_unsupported`
189+
(vendored). The lock now keeps its BOM, indent and line endings, and the
190+
undo is byte-exact (#324).
191+
- `vendor` under `--global` / `--global-prefix` (or `SOCKET_GLOBAL` /
192+
`SOCKET_GLOBAL_PREFIX`) is now a usage error (exit 2,
193+
`global_scope_unsupported`), like `scan` and `get` with `--mode vendored`.
194+
Run inside a project, `vendor -g` vendored the manifest's records into that
195+
project and rewired its lockfile, and `vendor --revert -g` unwound the
196+
project's vendoring, so its next frozen install was silently unpatched.
197+
Global installs have no project lockfile to vendor into (#498).
165198

166199
### Maintenance
167200

0 commit comments

Comments
 (0)