Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Global mode never finds yarn 1.0.x global packages: `yarn global dir` doesn't exist before yarn 1.1.0, and there's no fallback

Ouverte
#437 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
68/100
Type d'issue
Bug
Clarté
Clairement spécifiée
Activité
Active
Stack technique
rust
Domaine
cli, tooling

Piste de recherche

Start in crates/socket-patch-core/src/crawlers/npm_crawler.rs at lines 514 and 1151, then review the existing global-mode tests and yarn-classic-matrix coverage. Reproduce the yarn 1.0.2 case from the issue and compare it with yarn 1.1.0. Done means supported yarn 1.0.x global packages are found or the scan warns instead of reporting a clean success, without regressing the existing matrix.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

agent:triaged bug bughunt pm:yarn-classic priority:p1

[agent] Found by the scheduled Yarn classic (1.x) bug-hunt routine (ledger #304).

Summary

scan -g, scan -g --mode agent, get -g, rollback -g and vex -g find yarn's global packages only by running yarn global dir. That subcommand doesn't exist in yarn 1.0.0–1.0.2: it prints error Invalid subcommand. Try "add, bin, ls, list, remove, upgrade, upgrade-interactive" and exits 1. The lookup then returns None, nothing else probes yarn's global folder, and every package installed with yarn global add is silently left out. Every command exits 0 with status: success.

Yarn 1.1.0 added yarn global dir. I bisected through corepack: 1.0.2 exits 1, while 1.1.0, 1.2.1, 1.3.2, 1.4.0, 1.5.1 and 1.6.0 print the folder. The folder itself (~/.config/yarn/global, or /usr/local/share/.config/yarn/global for root, %LOCALAPPDATA%\Yarn\Data\global on Windows) hasn't moved between 1.0 and 1.1.

Impact

It's a silent miss. On a machine with yarn 1.0.x, scan -g reports no patchable yarn-global tools, and scan -g --mode agent exits 0 with applied: 0 while the global copy stays vulnerable. The routine's version range (and CI's yarn-classic-matrix, which starts at 1.0.2) treats 1.0.x as supported, and docs/ecosystems.md doesn't mention this limitation. Yarn 1.0.x is old (2017), so this is low priority, but the result is a false all-clear rather than a refusal.

Repro (Linux sandbox, main 2463257)

corepack [email protected] global add [email protected]   # lands in /usr/local/share/.config/yarn/global/node_modules (root)
corepack [email protected] global dir                    # error Invalid subcommand …   (exit 1)
# with `yarn` on PATH = yarn 1.0.2, mock patch API serving pkg:npm/[email protected]:
socket-patch scan -g $API --json                  # status success, packages []           <- miss
socket-patch scan -g --mode agent $API --json     # status success, apply.applied 0, exit 0
head -1 /usr/local/share/.config/yarn/global/node_modules/is-number/index.js   # still upstream
# same machine, same global folder, `yarn` = 1.1.0:
socket-patch scan -g $API --json                  # packages ["pkg:npm/[email protected]"]  <- found

Expected vs actual

  • Expected: CLI_CONTRACT.md documents --global as "Operate on globally-installed packages", with --global-prefix defaulting to "(auto)". The global-mode checklist (ledger #304) requires scan -g to find every globally installed package, with none missing. When yarn is on PATH but yarn global dir fails, socket-patch should fall back to yarn's default global folder (or yarn global bin's sibling, or .yarnrc global-folder). Failing that, it should warn that yarn's global folder couldn't be determined, rather than report a clean scan.
  • Actual: yarn-global packages are invisible, with exit 0.

OS × yarn matrix (probe run, plus the Linux sandbox)

OS yarn 1.0.2 yarn 1.10.1 yarn 1.22.22
Linux (sandbox + ubuntu-latest) miss (scan_report, agent_apply, vex fail) pass pass
macOS (macos-latest) miss pass pass
Windows (windows-latest) miss (also #434) miss, see #434 miss, see #434

On Windows every yarn version misses, for a separate reason: the bare yarn spawn never resolves yarn.cmd, which is tracked in #434. 1.0.x would still miss after that fix.

Suspect code

  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:514: get_yarn_global_prefix_with runs only yarn global dir. None (non-zero exit) is final.
  • crates/socket-patch-core/src/crawlers/npm_crawler.rs:1151: get_global_node_modules_paths has no yarn fallback. The only fallbacks are the macOS-only npm ones.

Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36827174726 (jobs global * yarn 1.0.2 print global dir: yarn global v1.0.2 … /node_modules and scan_report … result=FAIL).

Langage dominant
Rust
Étoiles
8
Forks
0
Merge moyen
15 h 39 min
PR mergées (30 j)
104

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de SocketDev/socket-patch

Toutes les issues de SocketDev/socket-patch

Issues similaires

Plus d'issues Rust

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.