Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Yarn berry vendored and hosted modes refuse `compressionLevel: 0 # comment` in .yarnrc.yml as a non-default compression level

Abierto Apto para principiantes
#370 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
82/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
rust
Área
cli, tooling

Línea de trabajo

Comienza en crates/socket-patch-core/src/vendor/yarn_berry_lock.rs:1307, en yarnrc_compression_level, y ejecuta la reproducción proporcionada de Yarn Berry con los entry points vendored y hosted. Verifica que un comentario YAML final quede excluido del nivel de compresión, mientras que compressionLevel: 0 siga siendo aceptado y ambos modos finalicen correctamente.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

agent:triaged bug bughunt pm:yarn-berry priority:p1

[agent] Found by the scheduled Yarn Berry (2+) bug-hunt routine (ledger #305).

Summary

Suppose .yarnrc.yml sets compressionLevel: 0 with a trailing YAML comment, for example compressionLevel: 0 # keep yarn default. Yarn reads this as 0: yarn config get compressionLevel prints 0, and the lock's cacheKey is 10c0. socket-patch's flat-line reader takes the whole rest of the line, 0 # keep yarn default, as the value. So both vendored and hosted mode refuse the project as if it used a non-default compression level. The message contradicts itself:

vendor_yarn_berry_cache_unsupported: .yarnrc.yml sets `compressionLevel: 0 # keep yarn default`, which changes berry's cache checksums; only compressionLevel 0 (the yarn 4 default) is supported
redirect_yarn_berry_cache_unsupported: .yarnrc.yml sets `compressionLevel: 0 # keep yarn default`, …

Impact

A refusal fires on a supported configuration. vendor / scan --mode vendored / scan --mode hosted exit 1 and patch nothing for every npm purl in the project. Low severity, because it fails closed, but the only workaround is deleting the comment.

Repro (Linux, yarn 4.12.0 and 4.18.1)

echo '{"name":"app","version":"1.0.0","dependencies":{"left-pad":"1.3.0"}}' > package.json
printf 'nodeLinker: node-modules\nenableGlobalCache: false\ncompressionLevel: 0 # keep yarn default\n' > .yarnrc.yml
touch yarn.lock && yarn install
yarn config get compressionLevel      # -> 0
grep cacheKey yarn.lock               # -> cacheKey: 10c0
# stage .socket/manifest.json + blob for pkg:npm/[email protected]
socket-patch vendor --json --offline  # -> exit 1, vendor_yarn_berry_cache_unsupported
socket-patch scan --mode hosted …     # -> exit 1, redirect_yarn_berry_cache_unsupported (mock API)

Without the comment, the same project vendors, and passes a fresh yarn install --immutable with the patched bytes.

Expected vs actual

  • Expected: docs/testing/yarn-berry-compatibility.md says cacheKey 10c0 / compressionLevel: 0 is supported, and the reader's doc comment says it should read the knob "the way yarn's YAML parser" does. A YAML comment isn't part of the scalar.
  • Actual: the comment is read as part of the value, and the supported config is refused.

Matrix

OS yarn vendored hosted
Linux (sandbox) 4.12.0 fails fails
Linux (sandbox) 4.18.1 not run fails

The parser is OS-independent. Release 4.0.0 behaves the same (vendored checked).

Suspect code

crates/socket-patch-core/src/vendor/yarn_berry_lock.rs:1307 (yarnrc_compression_level: rest.trim().trim_matches(['\'', '"']) doesn't strip a #… comment). The hosted gate shares it.

Lenguaje dominante
Rust
Estrellas
8
Forks
0
Merge medio
18 h 4 min
PR fusionados (30 d)
70

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de SocketDev/socket-patch

Todos los issues de SocketDev/socket-patch

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.