`scan --mode hosted --dry-run --vex <path> --json` drops the documented `vex: {skipped: true, reason: "dry_run"}` marker (agent and vendored scans emit it)
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Accessibilité débutants
- 83/100
Piste de recherche
Lisez l’assemblage du JSON du scan hébergé dans crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360 et comparez sa gestion de VEX avec scan/mod.rs:368-370 et scan/vendor_flow.rs:542-543. Le test hébergé existant dans covgap_commands_scan_hosted.rs:1948 ne couvre que la sortie lisible par les humains ; ajoutez ou adaptez la couverture pour les exécutions à blanc en JSON. C’est terminé lorsque hosted scan --dry-run --vex ... --json inclut le marqueur documenté indiquant que l’élément a été ignoré, sans écrire de fichier VEX.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
[agent] Found by the scheduled Pipenv bug-hunt routine (ledger #313).
Summary
CLI_CONTRACT.md ("Embedded VEX", the "Built from the post-run state" bullet) says: "--dry-run skips generation on every host command (nothing was changed, and a preview must not write an attestation — scan --json marks it vex: {skipped: true, reason: "dry_run"})".
scan --mode vendored and scan --mode agent emit that marker. scan --mode hosted doesn't: its JSON envelope has no vex key at all, so a dry run looks exactly like a run without --vex. Human mode is fine, since it prints Skipping VEX generation (--dry-run: nothing was rewritten). Generation is skipped correctly, and no file is written. Only the JSON marker is missing.
I found this on Pipenv projects, but the code path is shared by every hosted ecosystem. A plain requirements.txt project behaves the same way.
Impact
Low. A JSON consumer (a CI wrapper or a bot that previews scan --mode hosted --vex …) can't tell "VEX was requested but skipped for the dry run" apart from "VEX was never requested". The mod.rs comment states the marker exists so as to keep "the request visible to JSON consumers instead of silently dropping it". Since v5 scan defaults to hosted, so a bare scan --dry-run --vex … --json hits this path.
Repro (Linux, main 045d7ec, local mock of the patch API serving six 1.16.0)
mkdir app && cd app
cat > Pipfile <<'EOF'
[[source]]
url = "https://pypi.org/simple"
verify_ssl = true
name = "pypi"
[packages]
six = "==1.16.0"
EOF
pipenv lock
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq '.vex, .redirect.dryRun'
# null
# true
socket-patch scan --mode vendored --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode agent --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 --json | jq .vex
# {"skipped": true, "reason": "dry_run"}
socket-patch scan --mode hosted --dry-run --yes --vex v.json --vex-product pkg:pypi/app@1 2>&1 | grep VEX
# Skipping VEX generation (--dry-run: nothing was rewritten).
Expected vs actual
- Expected (CLI_CONTRACT.md, Embedded VEX):
"vex": {"skipped": true, "reason": "dry_run"}in the hostedscan --jsonenvelope, as in the other two modes. - Actual: the
vexkey is missing. Exit 0,status: success, andredirect.dryRun: true.
Matrix (Linux, each run in a fresh project)
| Project | --mode hosted |
--mode vendored |
--mode agent |
|---|---|---|---|
| Pipfile.lock from Pipenv 2026.8.0 (run twice) | missing | marker | marker |
| Pipfile.lock from Pipenv 2018.11.26 | missing | marker | not run |
plain requirements.txt (six==1.16.0) |
missing | not run | not run |
macOS and Windows weren't probed. This is OS-independent JSON assembly.
First bad
Not bisected. The marker arrived in the agent and vendored arms with de316b4, and the hosted arm never got it.
Suspect code
crates/socket-patch-cli/src/commands/scan/hosted.rs:1241: VEX generation is gated on!common.dry_run, which is correct.crates/socket-patch-cli/src/commands/scan/hosted.rs:1346-1360: the JSON arm setsresult["vex"]only forSome(statements)orvex_error. It has nodry_runbranch, unlikescan/mod.rs:368-370andscan/vendor_flow.rs:542-543. The human arm (hosted.rs:1467) does handle the dry run.- The existing test (
covgap_commands_scan_hosted.rs:1948,human_dry_run_prints_would_rewrite_pnpm_guidance_and_vex_skip) covers only the human output.
- Langage dominant
- Rust
- Étoiles
- 8
- Forks
- 0
- Merge moyen
- 15 h 39 min
- PR mergées (30 j)
- 104
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de SocketDev/socket-patch
-
agent:triaged bug bughunt pm:cargo priority:p2
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
SocketDev/socket-patch#651 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
Vendored Hatch runs a `hatch` executable planted in the scanned projectPeut-être pris @mikolalysenko l’a pris il y a 2 jours. Ouverteagent:claimed agent:triaged arch-audit bug pm:hatch priority:p1
Difficulté 2/5 Une demi-journée Accessibilité débutants 88/100
SocketDev/socket-patch#613 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
Patch blob and diff downloads buffer the whole response body with no size capPeut-être pris @mikolalysenko l’a pris il y a 2 jours. Ouverteagent:claimed agent:triaged arch-audit bug priority:p3
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
SocketDev/socket-patch#571 · 5 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
agent:triaged bug bughunt pm:composer priority:p2
Difficulté 2/5 1-3 heures Accessibilité débutants 90/100
SocketDev/socket-patch#515 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global installPeut-être pris Une pull request liée à cette issue est ouverte ou déjà fusionnée. Ouverteagent:triaged bug bughunt pm:npm priority:p1
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
SocketDev/socket-patch#464 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de SocketDev/socket-patch
Issues similaires
-
security-scan
Difficulté 2/5 1-3 heures Accessibilité débutants 68/100
Les mainteneurs répondent en général sous 1 jour
-
content good first issue
Difficulté 2/5 Moins d'une heure Accessibilité débutants 68/100
StudentSuite/awesome-skills-plugins-for-students#293 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
gfx-rs/wgpu-native#636 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
Les mainteneurs répondent en général sous 1 jour