`scan --mode hosted --dry-run --vex <path> --json` drops the documented `vex: {skipped: true, reason: "dry_run"}` marker (agent and vendored scans emit it)
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 83/100
Línea de trabajo
Lee el ensamblado del JSON del scan alojado en crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360 y compara su gestión de VEX con scan/mod.rs:368-370 y scan/vendor_flow.rs:542-543. La prueba alojada existente en covgap_commands_scan_hosted.rs:1948 solo cubre la salida legible para humanos; añade o adapta la cobertura para ejecuciones en seco de JSON. Está listo cuando hosted scan --dry-run --vex ... --json incluya el marcador documentado de omitido sin escribir un archivo VEX.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).
Summary
CLI_CONTRACT.md ("Embedded VEX", the "Built from the post-run state" bullet) says: "--dry-run skips generation on every host command (nothing was changed, and a preview must not write an attestation — scan --json marks it vex: {skipped: true, reason: "dry_run"})".
scan --mode vendored and scan --mode agent emit that marker. scan --mode hosted doesn't: its JSON envelope has no vex key at all, so a dry run looks exactly like a run without --vex. Human mode is fine, since it prints Skipping VEX generation (--dry-run: nothing was rewritten). Generation is skipped correctly, and no file is written. Only the JSON marker is missing.
I found this on Pipenv projects, but the code path is shared by every hosted ecosystem. A plain requirements.txt project behaves the same way.
Impact
Low. A JSON consumer (a CI wrapper or a bot that previews scan --mode hosted --vex …) can't tell "VEX was requested but skipped for the dry run" apart from "VEX was never requested". The mod.rs comment states the marker exists so as to keep "the request visible to JSON consumers instead of silently dropping it". Since v5 scan defaults to hosted, so a bare scan --dry-run --vex … --json hits this path.
Repro (Linux, main 045d7ec, local mock of the patch API serving six 1.16.0)
mkdir app && cd app
cat > Pipfile <<'EOF'
[[source]]
url = "https://pypi.org/simple"
verify_ssl = true
name = "pypi"
[packages]
six = "==1.16.0"
EOF
pipenv lock
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq '.vex, .redirect.dryRun'
# null
# true
socket-patch scan --mode vendored --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode agent --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 2>&1 | grep VEX
# Skipping VEX generation (--dry-run: nothing was rewritten).
Expected vs actual
- Expected (CLI_CONTRACT.md, Embedded VEX):
"vex": {"skipped": true, "reason": "dry_run"}in the hostedscan --jsonenvelope, as in the other two modes. - Actual: the
vexkey is missing. Exit 0,status: success, andredirect.dryRun: true.
Matrix (Linux, each run in a fresh project)
| Project | --mode hosted |
--mode vendored |
--mode agent |
|---|---|---|---|
| Pipfile.lock from Pipenv 2026.8.0 (run twice) | missing | marker | marker |
| Pipfile.lock from Pipenv 2018.11.26 | missing | marker | not run |
plain requirements.txt (six==1.16.0) |
missing | not run | not run |
macOS and Windows weren't probed. This is OS-independent JSON assembly.
First bad
Not bisected. The marker arrived in the agent and vendored arms with de316b4, and the hosted arm never got it.
Suspect code
crates/socket-patch-cli/src/commands/scan/hosted.rs:1241: VEX generation is gated on!common.dry_run, which is correct.crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360: the JSON arm setsresult["vex"]only forSome(statements)orvex_error. It has nodry_runbranch, unlikescan/mod.rs:368-370andscan/vendor_flow.rs:542-543. The human arm (hosted.rs:1467) does handle the dry run.- The existing test (
covgap_commands_scan_hosted.rs:1948,human_dry_run_prints_would_rewrite_pnpm_guidance_and_vex_skip) covers only the human output.
- Lenguaje dominante
- Rust
- Estrellas
- 8
- Forks
- 0
- Merge medio
- 1 d 1 h
- PR fusionados (30 d)
- 211
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de SocketDev/socket-patch
-
arch-audit refactor
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
SocketDev/socket-patch#1011 ·
Los mantenedores suelen responder en 1 día
-
agent:triaged arch-audit bug priority:p3
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
SocketDev/socket-patch#982 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap)Posiblemente ocupada @mikolalysenko la tomó hace 1 día. Abiertoagent:claimed agent:triaged bug bughunt pm:yarn-classic priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
SocketDev/socket-patch#907 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:bundler priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
SocketDev/socket-patch#896 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Dificultad 2/5 1-3 horas Aptitud para principiantes 73/100
SocketDev/socket-patch#783 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de SocketDev/socket-patch
Issues similares
-
documentation
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
fastrevmd-lab/rustmistmcp#161 ·
-
bug user-priority/P2
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
Los mantenedores suelen responder en 1 día
-
opencode: an unanswered --version probe launches opencode 2 without per-session service isolationAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
security-advisory
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
MinBZK/regelrecht#1686 ·
Los mantenedores suelen responder en 1 día
-
L: github:actions L: php:composer
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
dependabot/dependabot-core#16493 ·
Los mantenedores suelen responder en 1 día