Restore SFW blocking tests after Socket API errors are fixed
维护者通常 1 天内回复
@fengmk2 已经在做这个了。
开始于 2026年9月16日。
评估
这个 Issue 还没有评估数据。
描述
Restore the SFW malicious-package blocking checks after the Socket alert API failure is resolved.
Upstream report: https://github.com/SocketDev/sfw-free/issues/65.
Temporary skip: #162.
On 2026-09-16, sfw vp install lodahs returned exit code 0 without a block message. This failed the Linux, macOS, and Windows jobs in test-sfw-blocks-malicious, plus the final blocking check in test-sfw-with-socketdev-action.
The failed CI run and retry used Vite+ 0.3.2. The same package and tool versions passed the blocking check on 2026-09-15.
Direct checks with SFW 1.15.1 and 1.15.2 report:
Error occurred: error while fetching package alerts
{"errors":["Malformed Socket API response (Invalid input)"],"purlStrings":["pkg:npm/[email protected]"]}
The same error occurs with the alternatives crossenv, babelcli, mongose, axois, node-click, and webb3. SFW allows their security placeholder downloads. A benign control, [email protected], produces a normal packageAllowed event. These results indicate a failure in alert handling, so changing the test package does not resolve the failure.
To reproduce without executing package code, run this command with a fresh SFW process:
SFW_DEBUG=true sfw --verbose curl --fail --silent --show-error --max-time 25 \
https://registry.npmjs.org/lodahs/-/lodahs-0.0.1-security.tgz \
-o /dev/null
The temporary fix skips the test-sfw-blocks-malicious job and the final malicious-package assertion in test-sfw-with-socketdev-action. The other SFW setup and installation checks remain enabled.
Follow-up:
- Confirm that SFW can fetch alerts and block a documented test package. Update the pinned SFW version if the upstream fix requires it.
- Remove both temporary
if: ${{ false }}conditions from.github/workflows/test.yml. - Confirm a nonzero exit and the package-specific block message on Linux, macOS, and Windows, and through
socketdev/action.
Keep both assertions: a network error or registry 404 alone must not count as a successful SFW block.
- 主要语言
- TypeScript
- 星标
- 111
- 派生
- 22
- 平均合并
- 1 天 5 小时
- 30 天内合并 PR
- 31
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
voidzero-dev/setup-vp 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 48/100
voidzero-dev/setup-vp#164 · 1 条评论 ·
维护者通常 1 天内回复
-
RFC:Add minimum-release-age for Vite+ version selection可能已有人在做 @naokihaba 于 13 天前认领。 未关闭enhancement
voidzero-dev/setup-vp#155 · 5 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
Action is not verified by GitHub可能重新可做 @TheAlexLichter 于 33 天前认领,目前没有进行中的 PR。 未关闭
voidzero-dev/setup-vp#81 · 5 条评论 · 3 个 reaction · 已指派 1 人 ·
维护者通常 1 天内回复
-
Track: enable `sfw` on macOS/Windows once vp + sfw upstream TLS issues are resolved可能重新可做 @fengmk2 于 125 天前认领,目前没有进行中的 PR。 未关闭enhancement
voidzero-dev/setup-vp#73 · 1 个 reaction · 已指派 1 人 ·
维护者通常 1 天内回复
-
Support sh fallback for install script on Alpine可能重新可做 @fengmk2 于 187 天前认领,目前没有进行中的 PR。 未关闭
voidzero-dev/setup-vp#32 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 voidzero-dev/setup-vp 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
rohitg00/agentmemory#1428 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 86/100
boxlite-ai/boxlite#1729 ·
维护者通常 1 天内回复
-
detectors enhancement good first issue
难度 2/5 1-3 小时 新手友好度 86/100
SM260845/readme-gen#1 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
angular/angularfire#3774 ·
维护者通常 2 天内回复