Skip to content
Merged
Changes from 1 commit
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
c7d668e
feat(cli): add `scan --redirect` hosted-vendored-patch mode
mikolalysenko Jul 1, 2026
8fcd7b3
feat(vex): attest redirected patches with a (redirected) provenance m…
mikolalysenko Jul 1, 2026
7b23bc8
Merge remote-tracking branch 'origin/main' into feat/scan-redirect-mode
mikolalysenko Jul 1, 2026
b47b9d4
style: cargo fmt
mikolalysenko Jul 1, 2026
554b486
test(vex): real-install npm redirect capstone + docker gem/composer V…
mikolalysenko Jul 1, 2026
baedf28
fix(redirect,vex): fail-closed attestation, idempotent rewriters, sur…
mikolalysenko Jul 1, 2026
be23ae2
fix(ci): check the redirect golden fixtures out byte-exact on Windows
mikolalysenko Jul 1, 2026
e93f21c
chore: exclude test fixtures from Socket dependency scanning
mikolalysenko Jul 1, 2026
0c925d1
feat(cli): three-mode selector, maven hosted rewriter, nuget config f…
mikolalysenko Jul 2, 2026
a8dfb7e
feat(vendor): NuGet and Maven vendored backends with fragment-level r…
mikolalysenko Jul 2, 2026
1cfd02c
test: three-mode × ecosystem behavioral matrix
mikolalysenko Jul 2, 2026
a85f454
docs: three-mode README, CHANGELOG, CLI_CONTRACT + support matrix
mikolalysenko Jul 2, 2026
8399416
test(vendor): jsr is the unsupported-ecosystem exemplar now that nuge…
mikolalysenko Jul 2, 2026
56f3550
fix(cli): mode-conflict errors match the clap contract phrasing
mikolalysenko Jul 2, 2026
d9aa32f
docs: spell out Maven's checksum-failure fallback for hosted mode
mikolalysenko Jul 2, 2026
7ee80d7
refactor(core): factor bun text-lock grammar + share uri encode; gene…
mikolalysenko Jul 2, 2026
1db0d6d
feat(patches): Rush monorepo support — vendored refusal, scan invento…
mikolalysenko Jul 2, 2026
2716592
feat(core): yarn-berry + bun hosted registry-redirect rewriters + sha…
mikolalysenko Jul 2, 2026
20534a0
feat(cli): berry/bun redirect plumbing + bun.lockb auto-migration
mikolalysenko Jul 2, 2026
8154b18
feat(cli): scan --redirect discovers Rush pnpm locks + stale repo-sta…
mikolalysenko Jul 2, 2026
d6f736b
test(redirect,repair): pnpm hosted-lock legs + flavor repair matrix
mikolalysenko Jul 2, 2026
29bbb80
test(apply): agent-mode legs for bun, yarn-berry node-modules, rush farm
mikolalysenko Jul 2, 2026
58decbc
feat(redirect): fail-closed maven suffixing + trusted checksums
mikolalysenko Jul 2, 2026
bd317b8
test(redirect): real-install berry + bun hosted capstones
mikolalysenko Jul 2, 2026
dea45e6
test(docker): yarn berry 4.x agent + vendored e2e legs
mikolalysenko Jul 2, 2026
9063242
test(redirect): Rush hosted-mode redirect capstone (sim + gated real …
mikolalysenko Jul 2, 2026
bd76bcb
test(redirect): clippy cleanups in berry + rush redirect legs
mikolalysenko Jul 2, 2026
bf74543
docs: berry/bun + Rush hosted support, maven fail-closed, de-document…
mikolalysenko Jul 2, 2026
8f591de
style(core): satisfy clippy cloned_ref_to_slice_refs in rewriter tests
mikolalysenko Jul 2, 2026
14088c9
test(cli): fix windows + release CI failures in in-process suites
mikolalysenko Jul 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
chore: exclude test fixtures from Socket dependency scanning
The redirect golden fixtures commit manifests/lockfiles that
deliberately pin old, vulnerable dependency versions — they are the
test inputs for a security-patching tool. Socket's PR scan flagged
their CVEs (Puma, Flask) as project dependency alerts; socket.yml now
scopes scanning away from the fixture trees.

Assisted-by: Claude Code:claude-fable-5
  • Loading branch information
mikolalysenko committed Jul 1, 2026
commit e93f21c9dfe1c9bc567cd0701c14d0c75987cd57
11 changes: 11 additions & 0 deletions socket.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Socket (socket.dev) scanner configuration.
#
# The redirect golden fixtures commit manifests/lockfiles that DELIBERATELY
# pin old, vulnerable dependency versions — they are the test inputs for a
# security-patching tool, and the vulnerable pins are the point. Exclude them
# from dependency scanning so their CVEs don't block PRs as if they were real
# project dependencies.
version: 2
projectIgnorePaths:
- "crates/socket-patch-core/tests/fixtures/**"
- "crates/socket-patch-cli/tests/fixtures/**"
Loading