Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

`get <uuid>` overrides socket.yml without the documented `policy_bypassed` warning (purl/CVE/GHSA forms do warn)

Ouverte
#453 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 1 jour

Personne n'a encore pris cette issue.

Évaluation

Difficulté
3/5
Temps estimé
1-2 jours
Accessibilité débutants
78/100
Type d'issue
Bug
Clarté
Clairement spécifiée
Activité
Active
Stack technique
rust
Domaine
cli

Piste de recherche

Start in crates/socket-patch-cli/src/commands/get.rs:2603-2700, tracing the IdentifierType::Uuid mode branches and compare them with the search path reaching policy_bypass_warnings at lines 2929-2933. Reproduce the hosted, vendored, and agent commands from the issue with socket.yml excluding the package. Done means UUID get reports policy_bypassed in warnings[] and on stderr whenever policy would skip the package.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

agent:triaged bug bughunt pm:pipenv priority:p1

[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).

Summary

The contract says get ignores socket.yml but has to say so when it does. When the repo's socket.yml would have skipped the package, get must warn policy_bypassed, both in warnings[] and on stderr. The purl, CVE and GHSA forms of get do this. The UUID form doesn't. get <uuid> takes an early-return path straight into the mode dispatch, and that path never calls policy_bypass_warnings. The package gets patched in every mode (agent, hosted, vendored) with exit 0, no stderr line, and no warnings key in the --json envelope.

I found this on a Pipenv project, but the code path doesn't depend on the ecosystem.

Impact

policy_bypassed is the only signal that a run overrode the repository's rollout policy (ignorePackages, ecosystems, includePaths/ignorePaths, minSeverity, enabled: false). A UUID is the identifier that dashboards, bots and the scan table all hand out. So the most common scripted get can push a patch the repo explicitly excluded (for example enabled: false during a freeze) and leave nothing in CI logs or JSON output to flag it.

Repro (Linux, main 2463257, Pipenv 2026.8.0 project, local mock patch API)

git init -q proj && cd proj
# Pipfile + Pipfile.lock pinning six==1.16.0 (pipfile-spec 6)
printf 'version: 2\npatches:\n  ignorePackages: ["pkg:pypi/six"]\n' > socket.yml
socket-patch get pkg:pypi/[email protected] --mode hosted --yes --json | jq .warnings
#   ["(policy_bypassed) pkg:pypi/[email protected] would be skipped by socket.yml (policy_package_ignored: pkg:pypi/six (patches.ignorePackages)); get patches it anyway"]
git checkout Pipfile.lock 2>/dev/null || cp Pipfile.lock.orig Pipfile.lock
socket-patch get <uuid-of-that-patch> --mode hosted --yes --json | jq .warnings
#   null   (Pipfile.lock is rewritten, exit 0, nothing on stderr)

Results from two runs, each identical:

Command exit lock patched warnings[] policy_bypassed stderr warning
get pkg:pypi/[email protected] --mode hosted 0 yes yes yes
get pkg:pypi/[email protected] --mode vendored 0 yes yes yes
get <uuid> --mode hosted 0 yes missing missing
get <uuid> --mode vendored 0 yes missing missing
get <uuid> --mode agent 0 n/a (in place) missing missing

Expected vs actual

  • Expected: crates/socket-patch-cli/CLI_CONTRACT.md (socket.yml, "Commands") says: "get is explicit intent: it ignores the policy and warns policy_bypassed (in warnings[], and on stderr) when socket.yml would have skipped the package". docs/configuration.md says the same: "it bypasses policy and warns when a valid policy would exclude its target". Neither carves out the UUID form.
  • Actual: only the search-backed forms warn. The UUID form patches silently.

OS × version

OS Pipenv reproduces
Linux 2026.8.0 (SOCKET_PIPENV_MAJOR=2026) yes (2/2)
macOS / Windows — not probed. The code path is platform-independent.

First bad

socket.yml arrived with #277 (2463257) and isn't in any published release (v4.0.0 predates it). So the bug has been there since the feature landed.

Suspect code

  • crates/socket-patch-cli/src/commands/get.rs:2603-2700: the IdentifierType::Uuid branch returns from the match mode dispatch (save_and_apply_patch / run_get_hosted(…, &[], &[]) / run_get_vendored(…, &[], &[])) with empty warning lists.
  • crates/socket-patch-cli/src/commands/get.rs:2929-2933: the only call site of super::scan::policy::policy_bypass_warnings, which only the search path reaches.
Langage dominant
Rust
Étoiles
8
Forks
0
Merge moyen
18 h 4 min
PR mergées (30 j)
70

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de SocketDev/socket-patch

Toutes les issues de SocketDev/socket-patch

Issues similaires

Plus d'issues Rust

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.