Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

`get <uuid>` overrides socket.yml without the documented `policy_bypassed` warning (purl/CVE/GHSA forms do warn)

Offen
#453 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
78/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
rust
Bereich
cli

Rechercherichtung

Start in crates/socket-patch-cli/src/commands/get.rs:2603-2700, tracing the IdentifierType::Uuid mode branches and compare them with the search path reaching policy_bypass_warnings at lines 2929-2933. Reproduce the hosted, vendored, and agent commands from the issue with socket.yml excluding the package. Done means UUID get reports policy_bypassed in warnings[] and on stderr whenever policy would skip the package.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

agent:triaged bug bughunt pm:pipenv priority:p1

[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).

Summary

The contract says get ignores socket.yml but has to say so when it does. When the repo's socket.yml would have skipped the package, get must warn policy_bypassed, both in warnings[] and on stderr. The purl, CVE and GHSA forms of get do this. The UUID form doesn't. get <uuid> takes an early-return path straight into the mode dispatch, and that path never calls policy_bypass_warnings. The package gets patched in every mode (agent, hosted, vendored) with exit 0, no stderr line, and no warnings key in the --json envelope.

I found this on a Pipenv project, but the code path doesn't depend on the ecosystem.

Impact

policy_bypassed is the only signal that a run overrode the repository's rollout policy (ignorePackages, ecosystems, includePaths/ignorePaths, minSeverity, enabled: false). A UUID is the identifier that dashboards, bots and the scan table all hand out. So the most common scripted get can push a patch the repo explicitly excluded (for example enabled: false during a freeze) and leave nothing in CI logs or JSON output to flag it.

Repro (Linux, main 2463257, Pipenv 2026.8.0 project, local mock patch API)

git init -q proj && cd proj
# Pipfile + Pipfile.lock pinning six==1.16.0 (pipfile-spec 6)
printf 'version: 2\npatches:\n  ignorePackages: ["pkg:pypi/six"]\n' > socket.yml
socket-patch get pkg:pypi/[email protected] --mode hosted --yes --json | jq .warnings
#   ["(policy_bypassed) pkg:pypi/[email protected] would be skipped by socket.yml (policy_package_ignored: pkg:pypi/six (patches.ignorePackages)); get patches it anyway"]
git checkout Pipfile.lock 2>/dev/null || cp Pipfile.lock.orig Pipfile.lock
socket-patch get <uuid-of-that-patch> --mode hosted --yes --json | jq .warnings
#   null   (Pipfile.lock is rewritten, exit 0, nothing on stderr)

Results from two runs, each identical:

Command exit lock patched warnings[] policy_bypassed stderr warning
get pkg:pypi/[email protected] --mode hosted 0 yes yes yes
get pkg:pypi/[email protected] --mode vendored 0 yes yes yes
get <uuid> --mode hosted 0 yes missing missing
get <uuid> --mode vendored 0 yes missing missing
get <uuid> --mode agent 0 n/a (in place) missing missing

Expected vs actual

  • Expected: crates/socket-patch-cli/CLI_CONTRACT.md (socket.yml, "Commands") says: "get is explicit intent: it ignores the policy and warns policy_bypassed (in warnings[], and on stderr) when socket.yml would have skipped the package". docs/configuration.md says the same: "it bypasses policy and warns when a valid policy would exclude its target". Neither carves out the UUID form.
  • Actual: only the search-backed forms warn. The UUID form patches silently.

OS × version

OS Pipenv reproduces
Linux 2026.8.0 (SOCKET_PIPENV_MAJOR=2026) yes (2/2)
macOS / Windows — not probed. The code path is platform-independent.

First bad

socket.yml arrived with #277 (2463257) and isn't in any published release (v4.0.0 predates it). So the bug has been there since the feature landed.

Suspect code

  • crates/socket-patch-cli/src/commands/get.rs:2603-2700: the IdentifierType::Uuid branch returns from the match mode dispatch (save_and_apply_patch / run_get_hosted(…, &[], &[]) / run_get_vendored(…, &[], &[])) with empty warning lists.
  • crates/socket-patch-cli/src/commands/get.rs:2929-2933: the only call site of super::scan::policy::policy_bypass_warnings, which only the search path reaches.
Vorherrschende Sprache
Rust
Sterne
8
Forks
0
Ø Merge
19 Std. 56 Min.
Gemergte PRs (30 T.)
51

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus SocketDev/socket-patch

Alle Issues in SocketDev/socket-patch

Ähnliche Issues

Weitere Issues zu Rust

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.