Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Restore SFW blocking tests after Socket API errors are fixed

未关闭
#161 0 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

维护者通常 1 天内回复

@fengmk2 已经在做这个了。

开始于 2026年9月16日。

评估

这个 Issue 还没有评估数据。

描述

Restore the SFW malicious-package blocking checks after the Socket alert API failure is resolved.

Upstream report: https://github.com/SocketDev/sfw-free/issues/65.

Temporary skip: #162.

On 2026-09-16, sfw vp install lodahs returned exit code 0 without a block message. This failed the Linux, macOS, and Windows jobs in test-sfw-blocks-malicious, plus the final blocking check in test-sfw-with-socketdev-action.

The failed CI run and retry used Vite+ 0.3.2. The same package and tool versions passed the blocking check on 2026-09-15.

Direct checks with SFW 1.15.1 and 1.15.2 report:

Error occurred: error while fetching package alerts
{"errors":["Malformed Socket API response (Invalid input)"],"purlStrings":["pkg:npm/[email protected]"]}

The same error occurs with the alternatives crossenv, babelcli, mongose, axois, node-click, and webb3. SFW allows their security placeholder downloads. A benign control, [email protected], produces a normal packageAllowed event. These results indicate a failure in alert handling, so changing the test package does not resolve the failure.

To reproduce without executing package code, run this command with a fresh SFW process:

SFW_DEBUG=true sfw --verbose curl --fail --silent --show-error --max-time 25 \
  https://registry.npmjs.org/lodahs/-/lodahs-0.0.1-security.tgz \
  -o /dev/null

The temporary fix skips the test-sfw-blocks-malicious job and the final malicious-package assertion in test-sfw-with-socketdev-action. The other SFW setup and installation checks remain enabled.

Follow-up:

  • Confirm that SFW can fetch alerts and block a documented test package. Update the pinned SFW version if the upstream fix requires it.
  • Remove both temporary if: ${{ false }} conditions from .github/workflows/test.yml.
  • Confirm a nonzero exit and the package-specific block message on Linux, macOS, and Windows, and through socketdev/action.

Keep both assertions: a network error or registry 404 alone must not count as a successful SFW block.

主要语言
TypeScript
星标
111
派生
22
平均合并
1 天 5 小时
30 天内合并 PR
31

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

voidzero-dev/setup-vp 的其他 Issue

查看 voidzero-dev/setup-vp 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。