Repository navigation
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
feat(vendor): warn when a wired classic yarn.lock is one berry install from silent de-patching #133
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Uh oh!
There was an error while loading. Please reload this page.
feat(vendor): warn when a wired classic yarn.lock is one berry install from silent de-patching #133
Changes from all commits
de5f128File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
…l from silent de-patching Proven end-to-end on a real monorepo (2026-07): yarn 2+ (berry) migrates a classic (v1) yarn.lock to its own format on install and re-resolves every entry from the registry — the vendored `file:./.socket/vendor/…` resolutions are dropped with NO warning and every package installs unpatched. New state-based core probe `yarn_classic_berry_migration_risk` (vendor/mod.rs): fires when yarn.lock is classic AND carries vendored wiring AND package.json does not pin yarn classic via `packageManager: yarn@1…` (a corepack pin makes stray berry installs refuse instead of migrate; major is parsed, so yarn@10 does not string-match yarn@1). Reads on-disk state, not run events, so callers invoke it unconditionally at envelope-finalize: unwired projects, yarn@1-pinned projects, and fully-reverted runs stay silent. Surfaced as a new run-level `warnings` array on the JSON envelope (`{code, detail}`, omitted when empty so existing consumers see byte-identical output) plus a stderr line in human mode — wired into the `vendor` command and both scan vendor flows (shared run_scan_vendor_step). Tests: 5 probe unit tests (pin suppression, yarn@4/yarn@10/pnpm pins still warn, unwired/berry/missing locks silent, malformed package.json fails toward warning); the yarn-classic capstone e2e now asserts the advisory appears on first vendor AND on in-sync re-runs, disappears under a yarn@1.22.22 packageManager pin (and the empty array is omitted from JSON), and falls silent after --revert. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing