A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global install
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 82/100
Rechercherichtung
Beginne in crates/socket-patch-cli/src/commands/scan/render.rs bei report_only_hint(), und verfolge anschließend, wie scan den globalen und den --global-prefix-Geltungsbereich behandelt. Reproduziere den report-only-Hinweis mit dem bereitgestellten npm-Szenario und prüfe, dass seine Befehle den Geltungsbereich des Scans beibehalten. Fertig ist die Aufgabe, wenn das Befolgen des ausgegebenen Hinweises auf die globale Installation und nicht auf das aktuelle Projekt abzielt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
In v5, scan -g without --mode is report-only. When it finds patches, it ends with this hint:
To apply these patches in place, run:
socket-patch scan --mode agent [PATHS]
socket-patch get <package-name-or-purl-or-CVE-ID>
The global flag isn't in either command. If you run the hint as printed, it scans the current project: it prints No packages found… and exits 0 outside a project, and inside one it patches the project's copies. The global install stays unpatched. --global-prefix <dir> and SOCKET_GLOBAL=1 show the same hint.
The Yarn Berry routine reported this first (handover on ledger #302); I confirmed it with npm.
Impact
Low severity (UX), but it was introduced in v5. In v4.0.0, scan -g applied the patches itself. Someone upgrading follows the new hint, gets exit 0, and their global tools stay vulnerable with no error.
Repro (Linux, npm 10.9.4, Node 22.22, mock patch API)
P=$(mktemp -d); W=$(mktemp -d)
npm i -g --prefix "$P" [email protected]
cd "$W"
A="--api-url http://127.0.0.1:8765 --org o --api-token fake --patch-server-url http://127.0.0.1:8765"
NPM_CONFIG_PREFIX=$P socket-patch scan -g -e npm $A
# ...
# To apply these patches in place, run:
# socket-patch scan --mode agent [PATHS] <- no -g
# socket-patch get <package-name-or-purl-or-CVE-ID> <- no -g
NPM_CONFIG_PREFIX=$P socket-patch scan --mode agent --yes $A # the hint, verbatim
# No packages found. Run your package manager's install first. (exit 0)
head -c 20 "$P/lib/node_modules/left-pad/index.js" # still the upstream bytes
I ran it twice in fresh directories with the same result. With -g added (scan -g --mode agent), the global copy gets patched.
Expected vs actual
- Expected: the hint is a command that applies what the scan just reported. For a global scan that means
socket-patch scan -g --mode agentandsocket-patch get … -g, or--global-prefix <dir>when that's what was passed. The doc comment onreport_only_hintsays it's printed for "global with no mode", so it's meant for this case. - Actual: the commands have no scope flag, so they go to the project scope.
Matrix
| OS | npm | Binary | Result |
|---|---|---|---|
| Linux | 10.9.4 | main 2463257 |
❌ hint has no -g (with -g and with --global-prefix) |
| Linux | 10.9.4 | v4.0.0 | n/a: scan -g applies directly, no hint |
The hint is a fixed string, so the behaviour is the same on every OS.
First bad version
Main 2463257 (#277, the v5 consolidation). v4.0.0 doesn't print the hint.
Suspect code
crates/socket-patch-cli/src/commands/scan/render.rs:252 report_only_hint() takes no arguments and returns fixed strings. It needs the global and --global-prefix context so it can add the matching flag.
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 19 Std. 56 Min.
- Gemergte PRs (30 T.)
- 51
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#433 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:uv priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
SocketDev/socket-patch#408 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#370 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Hosted Gradle snippet is always Groovy DSL, so pasting it into a build.gradle.kts fails to compileOffenagent:triaged bug bughunt pm:gradle priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
SocketDev/socket-patch#348 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Same-GAV Maven patches are shadowed when a build plugin depends on the same GAV in a reactor buildOffenagent:triaged bug priority:p3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
SocketDev/socket-patch#274 ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
Maintainer antworten meist innerhalb von 3 Tagen
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
stellar/stellar-cli#2773 ·
Maintainer antworten meist innerhalb von 2 Tagen
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
smol-machines/smolvm#1503 · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag