@@ -102,6 +102,15 @@ limits, and required install commands.
102102
103103### Fixed
104104
105+ - Agent-mode PyPI ` apply ` patches every installed copy of a release, not just
106+ the first one found. A Pipenv project with both a WORKON_HOME venv and a
107+ ` ./.venv ` , or a global install with the same release in the user site and a
108+ system dir, no longer keeps the copy Python imports unpatched while ` vex `
109+ attests it (#529 , #501 ).
110+ - Gem hosted and vendored modes wire only the manifest Bundler loads. A ` gems.rb `
111+ twin or a ` BUNDLE_GEMFILE ` setting (environment or ` .bundle/config ` ) no longer
112+ leads to an edit of an ignored ` Gemfile ` that reports success and attests an
113+ unpatched gem; unsupported layouts are refused before any write (#341 , #390 ).
105114- ** npm dependencies installed from git, a URL or ` file: ` are no longer
106115 reported patched.** npm installs such a dependency from the dependent's
107116 spec (` github:user/repo ` , ` https://…/x.tgz ` , ` file:… ` ) and ignores the
@@ -148,6 +157,9 @@ limits, and required install commands.
148157- Python rewrites preserve supported markers, groups, extras, source metadata, and
149158 integrity pins. Relocks, out-of-tree environments, and lock-only VEX are handled
150159 consistently with each installer's supported behavior.
160+ - Hosted Pipenv scans read the ` Pipfile ` , so a conflicting ` Pipfile.lock ` entry
161+ refuses the patch project-wide instead of half-redirecting a sibling
162+ ` requirements.txt ` (#333 ).
151163- Vendoring reuses valid committed artifacts during service outages. Updates do
152164 not build from a previous patch's modified bytes. Verified service artifacts
153165 keep their identity; integrity failures do not fall through to a local rebuild.
@@ -162,6 +174,27 @@ limits, and required install commands.
162174- Transient apply locks are removed on normal command exit; no-op scans and full
163175 reversal avoid leaving unused ` .socket/ ` state. Terminal output, telemetry
164176 timeouts, and update-check handling are more consistent.
177+ - Agent mode finds transitive npm packages in npm's linked store
178+ (` install-strategy=linked ` , ` node_modules/.store ` ) and in a relocated pnpm
179+ ` virtualStoreDir ` , instead of reporting them ` package_not_installed ` (#359 ,
180+ #362 ). A store outside the project, such as pnpm's global virtual store, is
181+ shared with other projects and is still not patched in place.
182+ - npm locks keep their own layout when edited. ` scan --mode hosted ` ,
183+ ` scan --mode vendored ` , ` rollback ` and ` vendor --revert `
184+ re-serialized ` package-lock.json ` / ` npm-shrinkwrap.json ` with LF line
185+ endings (and, in hosted mode, a fixed 2-space indent), so a CRLF or
186+ tab-indented lock got a whole-file diff and the undo did not restore its
187+ bytes. A lock with a UTF-8 BOM, which npm installs from, was skipped as
188+ unparseable (hosted) or refused as ` vendor_lockfile_version_unsupported `
189+ (vendored). The lock now keeps its BOM, indent and line endings, and the
190+ undo is byte-exact (#324 ).
191+ - ` vendor ` under ` --global ` / ` --global-prefix ` (or ` SOCKET_GLOBAL ` /
192+ ` SOCKET_GLOBAL_PREFIX ` ) is now a usage error (exit 2,
193+ ` global_scope_unsupported ` ), like ` scan ` and ` get ` with ` --mode vendored ` .
194+ Run inside a project, ` vendor -g ` vendored the manifest's records into that
195+ project and rewired its lockfile, and ` vendor --revert -g ` unwound the
196+ project's vendoring, so its next frozen install was silently unpatched.
197+ Global installs have no project lockfile to vendor into (#498 ).
165198
166199### Maintenance
167200
0 commit comments