Restore SFW blocking tests after Socket API errors are fixed
メンテナーはふだん 1 日以内に返信
@fengmk2 がすでに取り組んでいます。
2026年9月16日 から。
評価
この issue はまだ評価されていません。
説明
Restore the SFW malicious-package blocking checks after the Socket alert API failure is resolved.
Upstream report: https://github.com/SocketDev/sfw-free/issues/65.
Temporary skip: #162.
On 2026-09-16, sfw vp install lodahs returned exit code 0 without a block message. This failed the Linux, macOS, and Windows jobs in test-sfw-blocks-malicious, plus the final blocking check in test-sfw-with-socketdev-action.
The failed CI run and retry used Vite+ 0.3.2. The same package and tool versions passed the blocking check on 2026-09-15.
Direct checks with SFW 1.15.1 and 1.15.2 report:
Error occurred: error while fetching package alerts
{"errors":["Malformed Socket API response (Invalid input)"],"purlStrings":["pkg:npm/[email protected]"]}
The same error occurs with the alternatives crossenv, babelcli, mongose, axois, node-click, and webb3. SFW allows their security placeholder downloads. A benign control, [email protected], produces a normal packageAllowed event. These results indicate a failure in alert handling, so changing the test package does not resolve the failure.
To reproduce without executing package code, run this command with a fresh SFW process:
SFW_DEBUG=true sfw --verbose curl --fail --silent --show-error --max-time 25 \
https://registry.npmjs.org/lodahs/-/lodahs-0.0.1-security.tgz \
-o /dev/null
The temporary fix skips the test-sfw-blocks-malicious job and the final malicious-package assertion in test-sfw-with-socketdev-action. The other SFW setup and installation checks remain enabled.
Follow-up:
- Confirm that SFW can fetch alerts and block a documented test package. Update the pinned SFW version if the upstream fix requires it.
- Remove both temporary
if: ${{ false }}conditions from.github/workflows/test.yml. - Confirm a nonzero exit and the package-specific block message on Linux, macOS, and Windows, and through
socketdev/action.
Keep both assertions: a network error or registry 404 alone must not count as a successful SFW block.
- 主要言語
- TypeScript
- スター
- 111
- フォーク
- 22
- 平均マージ
- 1日 1時間
- マージ済み PR(30日)
- 28
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
voidzero-dev/setup-vp のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
voidzero-dev/setup-vp#164 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
RFC:Add minimum-release-age for Vite+ version selection対応中かも @naokihaba が 18 日前に担当しました。 オープンenhancement
voidzero-dev/setup-vp#155 · コメント 5 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
Track: enable `sfw` on macOS/Windows once vp + sfw upstream TLS issues are resolved再び着手できるかも @fengmk2 が 129 日前に担当しましたが、オープン中のプルリクエストはありません。 オープンenhancement
voidzero-dev/setup-vp#73 · リアクション 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
Support sh fallback for install script on Alpine再び着手できるかも @fengmk2 が 192 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
voidzero-dev/setup-vp#32 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
voidzero-dev/setup-vp の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
Doist/todoist-cli#576 ·
メンテナーはふだん 1 日以内に返信
-
🐛 Bug supabase/cli
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
CopilotKit/aimock#491 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
agilepathway/label-checker#710 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信