You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Brings in #296, which removes dead code and the v3 compatibility
shims. The only conflict is CLI_CONTRACT's exit-code rows: they take
the base's text (no `--detached`, `--one-off` removed) plus the
socket.yml and SOCKET_MIN_SEVERITY rows. Clippy and the policy,
in-memory, parity, e2e policy, parser, help and scan suites pass.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BKsyzefGhAnPkYmXCwq3H3
| `--mode <hosted\|vendored\|agent>` | — | Selects one of the three [patch modes](#three-patch-modes) (default: `hosted`). Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. |
650
650
| `--package <name\|purl>` | `SOCKET_SCAN_PACKAGES` | Only scan these packages: a name (`lodash`, `@scope/pkg`, `requests`; case-insensitive) or a purl with or without its version (`pkg:npm/lodash`, `pkg:pypi/requests@2.31.0`). Repeat the flag or separate with commas. |
651
-
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff/package-archive files. [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
651
+
| `--prune` | — | Agent-mode garbage collection after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff-archive files (plus any legacy package archives). [Vendored](#vendor) packages are exempt from the crawl-based prune, but a vendored entry whose dependency has left the lockfile is reverted. Ignored, with a `redirect_prune_ignored` warning, in hosted mode; without a mode the scan is report-only. |
|`--batch-size <n>`|`SOCKET_BATCH_SIZE`| Packages per API request (default: `500` on the authenticated API, `100` on the public proxy). A request whose body would exceed 256 KiB is split into smaller ones. |
654
654
|`--min-severity <level>`|`SOCKET_MIN_SEVERITY`| Only patch packages whose patch fixes an advisory of at least `critical`, `high`, `medium` (or `moderate`) or `low`;`none` lifts the floor. Overrides `patches.minSeverity`in socket.yml. Patches of unknown severity are skipped whenever a floor is set. |
> `--vendor` (== `--mode vendored`). `--detached` is a hidden no-op kept for compatibility (vendored mode is
662
-
> always manifest-free); it is still an error without vendored mode.
661
+
> `--vendor` (== `--mode vendored`).
663
662
664
663
**Examples:**
665
664
```bash
@@ -973,7 +972,6 @@ socket-patch get <identifier> [options]
973
972
|`--ghsa`| — | Force identifier to be treated as a GHSA ID. |
974
973
|`-p, --package`| — | Force identifier to be treated as a package name. |
975
974
|`--save-only`|`SOCKET_SAVE_ONLY`| Download the patch without applying it (alias: `--no-apply`). |
976
-
|`--one-off`|`SOCKET_ONE_OFF`| Reserved (hidden from `--help`): apply the patch immediately without saving to the `.socket` folder. **Not yet implemented** — the command currently errors up front. |
977
975
|`--all-releases`|`SOCKET_ALL_RELEASES`| Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. |
978
976
|`--mode <hosted\|vendored\|agent>`| — | How to consume the patch; the same modes as `scan --mode` (default: `agent`). |
|`--preserve-state`|`SOCKET_PRESERVE_STATE`| Unpatch the system but keep the local patch state — manifest entries, vendored artifacts + ledger entries — for a later re-apply, and skip GC. Hosted patches have no preservable state (the lockfile is their only record) and are restored to upstream either way. |
1095
-
|`--one-off`|`SOCKET_ONE_OFF`| Reserved: rollback by fetching original (`beforeHash`) files from the API, no manifest required. **Not yet implemented** — the command currently errors up front. |
0 commit comments