You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* Remove the setup subcommand and its install hooks (v5 WS7)
`socket-patch setup` (and --check/--remove/--exclude) is gone, with every
install hook it wired: npm postinstall/dependencies scripts, the
socket-patch[hook] .pth wheel, the in-tree Bundler plugin + Gemfile block,
and Composer post-install/update scripts. `apply` stays; agent mode in CI
is `scan --mode agent` once, then `socket-patch apply` after each install.
Deleted: commands/setup.rs, core setup/** and the setup-only package_json
helpers, the setup tests and setup-matrix suites, the setup-e2e feature,
the setup-matrix CI job, tests/setup_matrix and scripts/setup-matrix.sh.
vex's install-hook "Property 7" filter goes with it. The socket-patch-hook
wheel and socket-patch-bundler gem are dropped from the build and publish
workflows (sources kept, frozen, pending an owner decision).
Also the plan's small follow-ups: drop the core crate's deprecated
re-export aliases (and the CI grep that guarded them), the unused
utils::process::tool_command, the vacuous e2e_cargo/e2e_golang CI rows,
add the merged 01019627 and 9c2b4925 gem patches to the vendored
production e2e, and retire the backtest-poetry "known crawler gap" label.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
* Streamline the patch UI (v5 WS8)
- `-h` lists about eight options per command (`cli_command()` marks the
rest hide_short_help; `--help` is unchanged); `scan --apply/--vendor`
are hidden (still accepted).
- Human warnings drop the `(code)` tag (`Warning: …`, `GC: skipped: …`);
JSON keeps every code. Error lines keep theirs.
- Human text says "hosted", not "redirect" (JSON keys unchanged).
- npm's allow-remote notice is one line; `--verbose`/JSON keep the full
policy text.
- One `ui::next_steps` renderer for hosted and vendored results.
- Hosted and vendored `get` never prompt: top-ranked patch per package,
like scan, in JSON too. Agent-mode `get` keeps its picker and confirm.
- `list` with nothing to list says `No patches in this project. Run
\`socket-patch scan\`.` (exit codes unchanged: 1 missing, 0 empty).
- One cancel line (`ui::CANCELLED`) and one paid upsell (`ui::PAID_UPGRADE`).
- `get`'s self-enforced flag conflicts and `rollback --one-off` exit 2,
like every other usage error.
Docs: CLI_CONTRACT (human output conventions, exit codes, get prompts),
README, CHANGELOG [Unreleased], v5 plan status. Tests updated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
* Pin the real-vlt get_and_remove leg to --mode agent
`get <uuid>` defaults to hosted since v5, so the leg's in-place
patched/pristine assertions need agent mode spelled out.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
* Match the hosted-ledger persist-failure wording in two covgap tests
These chmod-guarded tests skip under root, so the WS8 wording change
("hosted redirect ledger" -> "hosted ledger") only showed up in CI.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
* Empty list exits 0; group help by task; document the setup upgrade
Review follow-ups:
- `list` on a project with no manifest and no ledger record is an empty
list: exit 0, the empty-project line (human) or the success envelope
with `events: []` (`--json`). Only an unreadable or invalid manifest
fails. Hosted mode writes no manifest, so this is the normal case.
- Root help groups the commands by task (patch, undo, ship, agent mode)
instead of calling get/rollback/remove "older agent-mode commands";
the subcommand list follows the same order. `-h` keeps --cwd,
--ecosystems and --offline, and moves `scan --prune` to --help.
- README gains "Upgrading from `setup`": move to hosted or keep agent
mode, and the exact hook to delete per ecosystem. The CHANGELOG and
the frozen hook/plugin READMEs link it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
* Carry the hosted wording and code-free warnings onto #280's new tests and docs
#280 added tests and contract lines with the pre-WS8 human strings
("Would redirect", "<purl> redirected, but its patch record ...",
`Warning (<code>): ...`). Switch them to this branch's conventions.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
* Give the cargo safety VEX baseline a vulnerability to attest
With setup's install-hook filter gone, the manifest-backed agent-mode
cargo patch attests, but the staged minimal manifest carries no
vulnerabilities, so vex ended no_applicable_patches (exit 1). Add one
vulnerability to the entry before the baseline run.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PQaKzoW5dSw9u5pgAAvVRj
---------
Co-authored-by: Claude <noreply@anthropic.com>
echo '::error::use the canonical module paths (crate::vendor, patch::redirect::golang_local, crate::telemetry, manifest::cleanup_blobs, api::date, crawlers::fuzzy_match); the old-path aliases exist only for external consumers'
74
-
exit 1
75
-
fi
76
58
77
59
# The napi addon is only ever loaded by Node, so cargo's own tests never
78
60
# exercise its JS loader or the engine/provider boundary.
0 commit comments