Skip to content

Commit d9dd0ff

Browse files
committed
Merge release/v5-prerelease (dead-code removal)
Brings in #296, which removes dead code and the v3 compatibility shims. The only conflict is CLI_CONTRACT's exit-code rows: they take the base's text (no `--detached`, `--one-off` removed) plus the socket.yml and SOCKET_MIN_SEVERITY rows. Clippy and the policy, in-memory, parity, e2e policy, parser, help and scan suites pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BKsyzefGhAnPkYmXCwq3H3
2 parents 0c5a8cd + 1e3ace6 commit d9dd0ff

153 files changed

Lines changed: 1510 additions & 3519 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎CHANGELOG.md‎

Lines changed: 33 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,33 @@ into the new version's section — see docs/releasing.md.
7979
`gem_setup` / `composer_setup` / `pth_hook` aliases are removed from
8080
`socket-patch-core`, along with the setup-only `npm_family` table column
8181
(`FileRow::detects_pnpm`) and `VLT_SETUP_MARKERS`.
82+
- **v3/v4 compatibility spellings are gone.**
83+
- The v3.0 legacy env names `SOCKET_PATCH_PROXY_URL`, `SOCKET_PATCH_DEBUG`
84+
and `SOCKET_PATCH_TELEMETRY_DISABLED` are no longer read and no longer
85+
print a deprecation warning. Use `SOCKET_PROXY_URL`, `SOCKET_DEBUG` and
86+
`SOCKET_TELEMETRY_DISABLED`.
87+
- The hidden `scan --redirect` flag (use `--mode hosted`) and the hidden
88+
no-op `scan --detached` flag (vendored mode is always manifest-free) are
89+
removed. Both are now unknown-flag usage errors (exit 2).
90+
- The hidden `--mode` values `host`, `redirect` and `vendor` on `scan` and
91+
`get` are rejected; only `hosted`, `vendored` and `agent` are accepted.
92+
The hidden `scan --apply` and `scan --vendor` spellings stay.
93+
- **`get --one-off` and `rollback --one-off`** (and `SOCKET_ONE_OFF`) are
94+
removed. They were never implemented and only failed with a usage error;
95+
`--one-off` is now an unknown-flag error (still exit 2) and
96+
`SOCKET_ONE_OFF` is ignored.
97+
- **`.socket/packages/` package archives are no longer read.** Nothing has
98+
written them for several releases. `apply`, `vendor` and `repair` stop
99+
probing and staging the directory, and `apply`'s JSON `appliedVia` loses
100+
its `"package"` value (`"diff"` or `"blob"` remain). The GC sweeps
101+
(`scan --prune`, `rollback`, `remove`, `repair`) delete any leftover
102+
`.socket/packages/` files whole (`rollback` and `scan --prune` still
103+
report them as `removedPackageArchives`).
104+
- **Core crate:** removed uncalled public helpers
105+
(`bun_lock::snapshot_binary_workspace_artifacts`, `vlt_lock_sniff_ok`,
106+
and several `lock_inventory::view` accessors) and the never-read
107+
`DepOverride::berry_zip_url` field (a `berryZipUrl` key in a patch
108+
reference still parses).
82109

83110
### Changed (BREAKING): patch UI streamlining
84111

@@ -96,10 +123,10 @@ into the new version's section — see docs/releasing.md.
96123
confirmation, in `--json` too (no `selection_required` outside agent
97124
mode). Agent-mode `get` keeps its picker and `Download and apply N
98125
patches?` prompt.
99-
- **`get` and `rollback` usage errors exit 2** (were 1): `get`'s
100-
`--id`/`--cve`/`--ghsa`/`--package` multi-select, `--one-off --save-only`,
101-
`--mode hosted|vendored --save-only`, `--one-off`, a malformed forced
102-
identifier, and `rollback --one-off`. Every usage error now exits 2.
126+
- **`get` usage errors exit 2** (were 1): `get`'s
127+
`--id`/`--cve`/`--ghsa`/`--package` multi-select,
128+
`--mode hosted|vendored --save-only` and a malformed forced identifier.
129+
Every usage error now exits 2.
103130
- **Human output:** warning lines no longer carry the `(code)` tag
104131
(`Warning: …`, `GC: skipped: …`); the codes stay in the JSON envelope.
105132
Error lines keep theirs (`Error (<code>): …`). Hosted mode is called "hosted", not "redirect", in human
@@ -502,9 +529,8 @@ into the new version's section — see docs/releasing.md.
502529
selected patch records are fetched into memory and every vendor-ledger entry
503530
carries `detached: true` plus the embedded `record` as its verification
504531
source, so a vendored project's footprint is `.socket/vendor/**` only. The
505-
former `--detached` opt-in is now the only vendored posture — the flag is
506-
hidden, accepted as a no-op for compatibility, and still a usage error
507-
without vendored mode. JSON uses the detached download vocabulary for both
532+
former `--detached` opt-in is now the only vendored posture, and the flag
533+
itself is removed (see "Removed"). JSON uses the detached download vocabulary for both
508534
commands (`downloaded: N`, `detached: true`, `patches[].action` =
509535
`downloaded` | `skipped` | `failed`). The vendor step vendors exactly what
510536
discovery selected — the "whole manifest is vendored" re-vendor from a

‎README.md‎

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -648,7 +648,7 @@ socket-patch scan [PATHS]... [options]
648648
|------|---------|-------------|
649649
| `--mode <hosted\|vendored\|agent>` | — | Selects one of the three [patch modes](#three-patch-modes) (default: `hosted`). Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. |
650650
| `--package <name\|purl>` | `SOCKET_SCAN_PACKAGES` | Only scan these packages: a name (`lodash`, `@scope/pkg`, `requests`; case-insensitive) or a purl with or without its version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`). Repeat the flag or separate with commas. |
651-
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff/package-archive files. [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
651+
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff-archive files (plus any legacy package archives). [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
652652
| `--sync` | — | Shorthand for `--mode agent --prune`: the one-flag agent-mode auto-update run. |
653653
| `--batch-size <n>` | `SOCKET_BATCH_SIZE` | Packages per API request (default: `500` on the authenticated API, `100` on the public proxy). A request whose body would exceed 256 KiB is split into smaller ones. |
654654
| `--min-severity <level>` | `SOCKET_MIN_SEVERITY` | Only patch packages whose patch fixes an advisory of at least `critical`, `high`, `medium` (or `moderate`) or `low`; `none` lifts the floor. Overrides `patches.minSeverity` in socket.yml. Patches of unknown severity are skipped whenever a floor is set. |
@@ -658,8 +658,7 @@ socket-patch scan [PATHS]... [options]
658658
| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. |
659659
660660
> Deprecated, hidden spellings (still accepted): `--apply` (== `--mode agent`) and
661-
> `--vendor` (== `--mode vendored`). `--detached` is a hidden no-op kept for compatibility (vendored mode is
662-
> always manifest-free); it is still an error without vendored mode.
661+
> `--vendor` (== `--mode vendored`).
663662
664663
**Examples:**
665664
```bash
@@ -973,7 +972,6 @@ socket-patch get <identifier> [options]
973972
| `--ghsa` | — | Force identifier to be treated as a GHSA ID. |
974973
| `-p, --package` | — | Force identifier to be treated as a package name. |
975974
| `--save-only` | `SOCKET_SAVE_ONLY` | Download the patch without applying it (alias: `--no-apply`). |
976-
| `--one-off` | `SOCKET_ONE_OFF` | Reserved (hidden from `--help`): apply the patch immediately without saving to the `.socket` folder. **Not yet implemented** — the command currently errors up front. |
977975
| `--all-releases` | `SOCKET_ALL_RELEASES` | Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. |
978976
| `--mode <hosted\|vendored\|agent>` | — | How to consume the patch; the same modes as `scan --mode` (default: `agent`). |
979977
@@ -1092,7 +1090,6 @@ socket-patch rollback [targets]... [options]
10921090
| Flag | Env var | Description |
10931091
|------|---------|-------------|
10941092
| `--preserve-state` | `SOCKET_PRESERVE_STATE` | Unpatch the system but keep the local patch state — manifest entries, vendored artifacts + ledger entries — for a later re-apply, and skip GC. Hosted patches have no preservable state (the lockfile is their only record) and are restored to upstream either way. |
1095-
| `--one-off` | `SOCKET_ONE_OFF` | Reserved: rollback by fetching original (`beforeHash`) files from the API, no manifest required. **Not yet implemented** — the command currently errors up front. |
10961093
10971094
**Examples:**
10981095
```bash

0 commit comments

Comments
 (0)