`scan --mode hosted --dry-run --vex <path> --json` drops the documented `vex: {skipped: true, reason: "dry_run"}` marker (agent and vendored scans emit it)
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 83/100
Rechercherichtung
Lesen Sie die Zusammenstellung des gehosteten Scan-JSON in crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360 und vergleichen Sie deren VEX-Behandlung mit scan/mod.rs:368-370 und scan/vendor_flow.rs:542-543. Der bestehende gehostete Test in covgap_commands_scan_hosted.rs:1948 deckt nur die menschenlesbare Ausgabe ab; fügen Sie eine Abdeckung für JSON-Trockenläufe hinzu oder passen Sie sie an. Erledigt, wenn hosted scan --dry-run --vex ... --json den dokumentierten übersprungenen Marker enthält, ohne eine VEX-Datei zu schreiben.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).
Summary
CLI_CONTRACT.md ("Embedded VEX", the "Built from the post-run state" bullet) says: "--dry-run skips generation on every host command (nothing was changed, and a preview must not write an attestation — scan --json marks it vex: {skipped: true, reason: "dry_run"})".
scan --mode vendored and scan --mode agent emit that marker. scan --mode hosted doesn't: its JSON envelope has no vex key at all, so a dry run looks exactly like a run without --vex. Human mode is fine, since it prints Skipping VEX generation (--dry-run: nothing was rewritten). Generation is skipped correctly, and no file is written. Only the JSON marker is missing.
I found this on Pipenv projects, but the code path is shared by every hosted ecosystem. A plain requirements.txt project behaves the same way.
Impact
Low. A JSON consumer (a CI wrapper or a bot that previews scan --mode hosted --vex …) can't tell "VEX was requested but skipped for the dry run" apart from "VEX was never requested". The mod.rs comment states the marker exists so as to keep "the request visible to JSON consumers instead of silently dropping it". Since v5 scan defaults to hosted, so a bare scan --dry-run --vex … --json hits this path.
Repro (Linux, main 045d7ec, local mock of the patch API serving six 1.16.0)
mkdir app && cd app
cat > Pipfile <<'EOF'
[[source]]
url = "https://pypi.org/simple"
verify_ssl = true
name = "pypi"
[packages]
six = "==1.16.0"
EOF
pipenv lock
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq '.vex, .redirect.dryRun'
# null
# true
socket-patch scan --mode vendored --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode agent --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 2>&1 | grep VEX
# Skipping VEX generation (--dry-run: nothing was rewritten).
Expected vs actual
- Expected (CLI_CONTRACT.md, Embedded VEX):
"vex": {"skipped": true, "reason": "dry_run"}in the hostedscan --jsonenvelope, as in the other two modes. - Actual: the
vexkey is missing. Exit 0,status: success, andredirect.dryRun: true.
Matrix (Linux, each run in a fresh project)
| Project | --mode hosted |
--mode vendored |
--mode agent |
|---|---|---|---|
| Pipfile.lock from Pipenv 2026.8.0 (run twice) | missing | marker | marker |
| Pipfile.lock from Pipenv 2018.11.26 | missing | marker | not run |
plain requirements.txt (six==1.16.0) |
missing | not run | not run |
macOS and Windows weren't probed. This is OS-independent JSON assembly.
First bad
Not bisected. The marker arrived in the agent and vendored arms with de316b4, and the hosted arm never got it.
Suspect code
crates/socket-patch-cli/src/commands/scan/hosted.rs:1241: VEX generation is gated on!common.dry_run, which is correct.crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360: the JSON arm setsresult["vex"]only forSome(statements)orvex_error. It has nodry_runbranch, unlikescan/mod.rs:368-370andscan/vendor_flow.rs:542-543. The human arm (hosted.rs:1467) does handle the dry run.- The existing test (
covgap_commands_scan_hosted.rs:1948,human_dry_run_prints_would_rewrite_pnpm_guidance_and_vex_skip) covers only the human output.
- Vorherrschende Sprache
- Rust
- Sterne
- 8
- Forks
- 0
- Ø Merge
- 1 T. 31 Min.
- Gemergte PRs (30 T.)
- 151
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus SocketDev/socket-patch
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 73/100
SocketDev/socket-patch#783 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:cargo priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
SocketDev/socket-patch#651 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:composer priority:p2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
SocketDev/socket-patch#515 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global installEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offenagent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#464 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
agent:triaged bug bughunt pm:npm priority:p1
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
SocketDev/socket-patch#433 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in SocketDev/socket-patch
Ähnliche Issues
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 74/100
-
review-drift
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
oxidecomputer/hansei#14 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
rubys/roundhouse#444 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Published hardy-bpa-server image is built without the file-cla featureEvtl. vergeben @EmbryoSpace hat das heute übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
ricktaylor/hardy#755 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 62/100
semaphoreci/docker-images#46 · 1 Kommentar ·