Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Global mode never finds yarn 1.0.x global packages: `yarn global dir` doesn't exist before yarn 1.1.0, and there's no fallback

Offen
#437 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
68/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
rust
Bereich
cli, tooling

Rechercherichtung

Start in crates/socket-patch-core/src/crawlers/npm_crawler.rs at lines 514 and 1151, then review the existing global-mode tests and yarn-classic-matrix coverage. Reproduce the yarn 1.0.2 case from the issue and compare it with yarn 1.1.0. Done means supported yarn 1.0.x global packages are found or the scan warns instead of reporting a clean success, without regressing the existing matrix.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

agent:triaged bug bughunt pm:yarn-classic priority:p1

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

scan -g, scan -g --mode agent, get -g, rollback -g and vex -g find yarn's global packages only by running yarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it prints error Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive" and exits 1. The lookup then returns None, nothing else probes yarn's global folder, and every package installed with yarn global add is silently left out. Every command exits 0 with status: success.

Yarn 1.1.0 added yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or /usr/local/share/.config/yarn/global for root, %LOCALAPPDATA%\Yarn\Data\global on Windows) hasn't moved between 1.0 and 1.1.

Impact

It's a silent miss. On a machine with yarn 1.0.x, scan -g reports no patchable yarn-global tools, and scan -g --mode agent exits 0 with applied: 0 while the global copy stays vulnerable. The routine's version range (and CI's yarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.

Repro (Linux sandbox, main 2463257)

corepack [email protected] global add [email protected]   # lands in /usr/local/share/.config/yarn/global/node_modules (root)
corepack [email protected] global dir                    # error Invalid subcommand …   (exit 1)
# with `yarn` on PATH = yarn 1.0.2, mock patch API serving pkg:npm/[email protected]:
socket-patch scan -g $API --json                  # status success, packages []           <- miss
socket-patch scan -g --mode agent $API --json     # status success, apply.applied 0, exit 0
head -1 /usr/local/share/.config/yarn/global/node_modules/is-number/index.js   # still upstream
# same machine, same global folder, `yarn` = 1.1.0:
socket-patch scan -g $API --json                  # packages ["pkg:npm/[email protected]"]  <- found

Expected vs actual

  • Expected: CLI_CONTRACT.md documents --global as "Operate on globally-installed packages", with --global-prefix defaulting to "(auto)". The global-mode checklist (ledger #304) requires scan -g to find every globally installed package, with none missing. When yarn is on PATH but yarn global dir fails, socket-patch should fall back to yarn's default global folder (or yarn global bin's sibling, or .yarnrc global-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan.
  • Actual: yarn-global packages are invisible, with exit 0.

OS × yarn matrix (probe run, plus the Linux sandbox)

OS yarn 1.0.2 yarn 1.10.1 yarn 1.22.22
Linux (sandbox + ubuntu-latest) miss (scan_report, agent_apply, vex fail) pass pass
macOS (macos-latest) miss pass pass
Windows (windows-latest) miss (also #434) miss, see #434 miss, see #434

On Windows every yarn version misses, for a separate reason: the bare yarn spawn never resolves yarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.

Suspect code

  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:514: get_yarn_global_prefix_with runs only yarn global dir. None (non-zero exit) is final.
  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151: get_global_node_modules_paths has no yarn fallback. The only fallbacks are the macOS-only npm ones.

Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs global * yarn 1.0.2 print global dir: yarn global v1.0.2 … /node_modules and scan_report … result=FAIL).

Vorherrschende Sprache
Rust
Sterne
8
Forks
0
Ø Merge
15 Std. 39 Min.
Gemergte PRs (30 T.)
104

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus SocketDev/socket-patch

Alle Issues in SocketDev/socket-patch

Ähnliche Issues

Weitere Issues zu Rust

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.