A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global install
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 82/100
Línea de trabajo
Comienza en crates/socket-patch-cli/src/commands/scan/render.rs, en report_only_hint(), y luego sigue cómo scan gestiona el ámbito global y el de --global-prefix. Reproduce la indicación report-only con el escenario de npm proporcionado y comprueba que sus comandos conservan el ámbito del análisis. La tarea estará terminada cuando seguir la indicación impresa apunte a la instalación global en lugar de al proyecto actual.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
In v5, scan -g without --mode is report-only. When it finds patches, it ends with this hint:
To apply these patches in place, run:
socket-patch scan --mode agent [PATHS]
socket-patch get <package-name-or-purl-or-CVE-ID>
The global flag isn't in either command. If you run the hint as printed, it scans the current project: it prints No packages found… and exits 0 outside a project, and inside one it patches the project's copies. The global install stays unpatched. --global-prefix <dir> and SOCKET_GLOBAL=1 show the same hint.
The Yarn Berry routine reported this first (handover on ledger #302); I confirmed it with npm.
Impact
Low severity (UX), but it was introduced in v5. In v4.0.0, scan -g applied the patches itself. Someone upgrading follows the new hint, gets exit 0, and their global tools stay vulnerable with no error.
Repro (Linux, npm 10.9.4, Node 22.22, mock patch API)
P=$(mktemp -d); W=$(mktemp -d)
npm i -g --prefix "$P" [email protected]
cd "$W"
A="--api-url http://127.0.0.1:8765 --org o --api-token fake --patch-server-url http://127.0.0.1:8765"
NPM_CONFIG_PREFIX=$P socket-patch scan -g -e npm $A
# ...
# To apply these patches in place, run:
# socket-patch scan --mode agent [PATHS] <- no -g
# socket-patch get <package-name-or-purl-or-CVE-ID> <- no -g
NPM_CONFIG_PREFIX=$P socket-patch scan --mode agent --yes $A # the hint, verbatim
# No packages found. Run your package manager's install first. (exit 0)
head -c 20 "$P/lib/node_modules/left-pad/index.js" # still the upstream bytes
I ran it twice in fresh directories with the same result. With -g added (scan -g --mode agent), the global copy gets patched.
Expected vs actual
- Expected: the hint is a command that applies what the scan just reported. For a global scan that means
socket-patch scan -g --mode agentandsocket-patch get … -g, or--global-prefix <dir>when that's what was passed. The doc comment onreport_only_hintsays it's printed for "global with no mode", so it's meant for this case. - Actual: the commands have no scope flag, so they go to the project scope.
Matrix
| OS | npm | Binary | Result |
|---|---|---|---|
| Linux | 10.9.4 | main 2463257 |
❌ hint has no -g (with -g and with --global-prefix) |
| Linux | 10.9.4 | v4.0.0 | n/a: scan -g applies directly, no hint |
The hint is a fixed string, so the behaviour is the same on every OS.
First bad version
Main 2463257 (#277, the v5 consolidation). v4.0.0 doesn't print the hint.
Suspect code
crates/socket-patch-cli/src/commands/scan/render.rs:252 report_only_hint() takes no arguments and returns fixed strings. It needs the global and --global-prefix context so it can add the matching flag.
- Lenguaje dominante
- Rust
- Estrellas
- 8
- Forks
- 0
- Merge medio
- 18 h 4 min
- PR fusionados (30 d)
- 70
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de SocketDev/socket-patch
-
agent:triaged bug bughunt pm:composer priority:p2
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
SocketDev/socket-patch#515 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:npm priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
SocketDev/socket-patch#433 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:uv priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
SocketDev/socket-patch#408 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
SocketDev/socket-patch#370 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Hosted Gradle snippet is always Groovy DSL, so pasting it into a build.gradle.kts fails to compileAbiertoagent:triaged bug bughunt pm:gradle priority:p3
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
SocketDev/socket-patch#348 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de SocketDev/socket-patch
Issues similares
-
component:sight
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
agentic-os-org/ANOLISA#4115 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
A-io-database bug needs triage python
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
Los mantenedores suelen responder en 1 día
-
Change output crossing a compactsize boundary leaves the fee slightly below the requested feerateAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
bitcoindevkit/bdk_wallet#578 ·
Los mantenedores suelen responder en 8 días
-
`python.analysis` setting changes (e.g. `completeFunctionParens`) are not picked up until reloadAbiertolanguage-server
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 2 días