Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Project-mode NuGet agent scan patches, and VEX attests, packages the project doesn't depend on (the crawler lists the whole ~/.nuget/packages)

Offen
#427 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
68/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
csharp, rust
Bereich
cli, devtools

Rechercherichtung

Start in crates/socket-patch-core/src/crawlers/nuget_crawler.rs:74-78 and inspect how obj/project.assets.json libraries and packageFolders could determine project packages. Run the provided Linux reproduction and verify project-mode discovery no longer crawls unrelated global-cache packages, patches them, or includes them in VEX output.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

agent:triaged bug bughunt pm:nuget priority:p3

[agent] Found by the scheduled NuGet / dotnet bug-hunt routine (ledger #320).

Summary

Without -g, NuGet discovery for a .NET project lists every package in the user-wide global packages folder (~/.nuget/packages, %USERPROFILE%\.nuget\packages), not just the packages the project resolves. So, in a project that depends only on Newtonsoft.Json:

  • scan reports and looks up [email protected], netstandard.library, … left over from unrelated projects on the same machine.
  • scan --mode agent --yes applies a patch to [email protected] in the shared cache, which the project never uses, and records it in this project's .socket/manifest.json. Exit 0, 1 of 1 targeted patch applied.
  • vex --product pkg:nuget/[email protected] then emits not_affected / inline_mitigations_already_exist with pkg:nuget/[email protected] as a subcomponent of App. App doesn't contain serilog.

This is the NuGet twin of #265 (Maven: "the crawler lists all of ~/.m2").

Impact

  • A false VEX: the product's attestation names components it doesn't ship. That pollutes SBOM/VEX consumers and can mask the real dependency set.
  • Agent mode mutates bytes in a cache shared by every other project on the machine. The patch is recorded against this project, so another project's rollback / repair doesn't know about it.
  • Noise: scan output and the patch-API batch carry the whole machine cache (hundreds of packages on a dev box or warm CI image).

Repro (Linux, dotnet SDK 8.0.131, main 2463257)

SP=/path/to/target/release/socket-patch
export SOCKET_NO_CONFIG=1 SOCKET_TELEMETRY_DISABLED=1
# another project on this machine uses Serilog
mkdir other && cd other && cat > O.csproj <<'X'
<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>net8.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="Serilog" Version="3.1.1" /></ItemGroup></Project>
X
dotnet restore && cd ..
# our project depends only on Newtonsoft.Json
mkdir app && cd app && cat > App.csproj <<'X'
<Project Sdk="Microsoft.NET.Sdk"><PropertyGroup><TargetFramework>netstandard2.0</TargetFramework></PropertyGroup><ItemGroup><PackageReference Include="Newtonsoft.Json" Version="13.0.3" /></ItemGroup></Project>
X
dotnet restore
grep -ci serilog obj/project.assets.json          # 0, not a dependency
# local stand-in for the public proxy (POST /patch/batch, GET /patch/by-package/<purl>,
# GET /patch/view/<uuid>) that serves one free patch for pkg:nuget/[email protected] (README.md + marker line)
$SP scan --mode agent --yes --proxy-url http://127.0.0.1:8766
#   Found 4 packages (4 nuget) ... Patched packages: pkg:nuget/[email protected] (via blob)
#   Summary: 1 of 1 targeted patch applied   (exit 0)
grep -c SOCKET_MARKER ~/.nuget/packages/serilog/3.1.1/README.md   # 1
$SP vex --offline --product pkg:nuget/[email protected]
#   products[0] = pkg:nuget/[email protected], subcomponents = [pkg:nuget/[email protected]], status not_affected

Reproduced twice (rollback in between restores the bytes exactly). scan --json without --mode (report-only / hosted) also lists the unrelated packages.

Expected vs actual

  • Expected: project-mode discovery covers the packages this project resolves. For PackageReference projects that's the libraries in obj/project.assets.json (or packages.lock.json); for packages.config, the packages/ folder. The VEX contract (README VEX section, CLI_CONTRACT.md) attests only what is patched in the product. The maintainers' global-mode note (ledger #320, 20261001T040000Z entry) also asks that a scan without -g never touch the global location beyond the project.
  • Actual: get_nuget_package_paths adds the whole global packages folder as a crawl root in local mode, and crawl_all emits every <id>/<ver>/ in it.

OS × SDK matrix

OS SDK unrelated cache package patched + attested
Linux (local) 8.0.131 yes (2/2 runs)

The crawler code path is OS-independent (the same nuget_home() root is used on macOS and Windows; the probe run https://github.com/SocketDev/socket-patch/actions/runs/36820498426 shows the same ~/.nuget/packages / C:\Users\runneradmin\.nuget\packages root being crawled on all 3 OSes). I haven't separately run this agent-mode scenario on macOS or Windows.

First bad version

Not a regression: v4.0.0 (scan --apply --yes) patches [email protected] the same way.

Suspect code

crates/socket-patch-core/src/crawlers/nuget_crawler.rs:74-78 (// 2. Fall back to the global cache. pushes nuget_home() as a crawl root in local mode). A fix would crawl only the <id>/<ver> dirs named in obj/project.assets.json libraries (resolved against its packageFolders) instead of the whole folder. That would also fix the wrong-folder half of #397.

Vorherrschende Sprache
Rust
Sterne
8
Forks
0
Ø Merge
19 Std. 56 Min.
Gemergte PRs (30 T.)
51

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus SocketDev/socket-patch

Alle Issues in SocketDev/socket-patch

Ähnliche Issues

Weitere Issues zu Rust

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.