A report-only `scan -g` tells you to run `socket-patch scan --mode agent [PATHS]` without `-g`, so following the hint scans the cwd project instead of the global install
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
研究方向
從 crates/socket-patch-cli/src/commands/scan/render.rs 中的 report_only_hint() 開始,接著追蹤 scan 如何處理全域範圍和 --global-prefix 範圍。使用提供的 npm 情境重現 report-only 提示,並檢查其中的命令是否保留掃描的範圍。當按照列印出的提示操作時,目標是全域安裝而不是目前的專案,即表示完成。
由索引模型根據 Issue 內容生成。
描述
[agent] Found by the scheduled npm bug-hunt routine (ledger #302).
Summary
In v5, scan -g without --mode is report-only. When it finds patches, it ends with this hint:
To apply these patches in place, run:
socket-patch scan --mode agent [PATHS]
socket-patch get <package-name-or-purl-or-CVE-ID>
The global flag isn't in either command. If you run the hint as printed, it scans the current project: it prints No packages found… and exits 0 outside a project, and inside one it patches the project's copies. The global install stays unpatched. --global-prefix <dir> and SOCKET_GLOBAL=1 show the same hint.
The Yarn Berry routine reported this first (handover on ledger #302); I confirmed it with npm.
Impact
Low severity (UX), but it was introduced in v5. In v4.0.0, scan -g applied the patches itself. Someone upgrading follows the new hint, gets exit 0, and their global tools stay vulnerable with no error.
Repro (Linux, npm 10.9.4, Node 22.22, mock patch API)
P=$(mktemp -d); W=$(mktemp -d)
npm i -g --prefix "$P" [email protected]
cd "$W"
A="--api-url http://127.0.0.1:8765 --org o --api-token fake --patch-server-url http://127.0.0.1:8765"
NPM_CONFIG_PREFIX=$P socket-patch scan -g -e npm $A
# ...
# To apply these patches in place, run:
# socket-patch scan --mode agent [PATHS] <- no -g
# socket-patch get <package-name-or-purl-or-CVE-ID> <- no -g
NPM_CONFIG_PREFIX=$P socket-patch scan --mode agent --yes $A # the hint, verbatim
# No packages found. Run your package manager's install first. (exit 0)
head -c 20 "$P/lib/node_modules/left-pad/index.js" # still the upstream bytes
I ran it twice in fresh directories with the same result. With -g added (scan -g --mode agent), the global copy gets patched.
Expected vs actual
- Expected: the hint is a command that applies what the scan just reported. For a global scan that means
socket-patch scan -g --mode agentandsocket-patch get … -g, or--global-prefix <dir>when that's what was passed. The doc comment onreport_only_hintsays it's printed for "global with no mode", so it's meant for this case. - Actual: the commands have no scope flag, so they go to the project scope.
Matrix
| OS | npm | Binary | Result |
|---|---|---|---|
| Linux | 10.9.4 | main 2463257 |
❌ hint has no -g (with -g and with --global-prefix) |
| Linux | 10.9.4 | v4.0.0 | n/a: scan -g applies directly, no hint |
The hint is a fixed string, so the behaviour is the same on every OS.
First bad version
Main 2463257 (#277, the v5 consolidation). v4.0.0 doesn't print the hint.
Suspect code
crates/socket-patch-cli/src/commands/scan/render.rs:252 report_only_hint() takes no arguments and returns fixed strings. It needs the global and --global-prefix context so it can add the matching flag.
- 主要語言
- Rust
- 星號
- 8
- 分支
- 0
- 平均合併
- 18 小時 4 分鐘
- 30 天內合併 PR
- 70
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
SocketDev/socket-patch 的其他 Issue
-
agent:triaged bug bughunt pm:composer priority:p2
難度 2/5 1-3 小時 新手友好度 90/100
SocketDev/socket-patch#515 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:npm priority:p1
難度 2/5 1-3 小時 新手友好度 82/100
SocketDev/socket-patch#433 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:uv priority:p1
難度 2/5 1-3 小時 新手友好度 78/100
SocketDev/socket-patch#408 · 1 則留言 ·
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
難度 2/5 1-3 小時 新手友好度 82/100
SocketDev/socket-patch#370 · 2 則留言 ·
維護者通常 1 天內回覆
-
Hosted Gradle snippet is always Groovy DSL, so pasting it into a build.gradle.kts fails to compile未關閉agent:triaged bug bughunt pm:gradle priority:p3
難度 2/5 1-3 小時 新手友好度 78/100
SocketDev/socket-patch#348 · 1 則留言 ·
維護者通常 1 天內回覆
查看 SocketDev/socket-patch 的全部 Issue
相似的 Issue
-
discover: `sudo RTK_DISABLED=$VAR …` is not detected as a bypass when `sudo` is a transparent prefix未關閉area:cli bug good first issue priority:medium
難度 2/5 1-3 小時 新手友好度 88/100
維護者通常 1 天內回覆
-
skill:code-review
難度 1/5 1-3 小時 新手友好度 88/100
維護者通常 1 天內回覆
-
component:sight
難度 2/5 1-3 小時 新手友好度 84/100
agentic-os-org/ANOLISA#4115 · 1 則留言 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 78/100
rivet-dev/rivet#5819 · 1 則留言 ·
維護者通常 1 天內回覆
-
A-io-database bug needs triage python
難度 2/5 1-3 小時 新手友好度 86/100
維護者通常 1 天內回覆