You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 48085ce
Browse filesBrowse the repository at this point in the historyBrowse files
Fix npm VEX attesting a patch the twin lock lacks (#798) (#799)
* Start fix for #798
Assisted-by: Claude Code:claude-opus-5-5
* Refuse npm VEX when the twin lock lacks the pkg
With both npm-shrinkwrap.json and package-lock.json committed,
lockfile-only `vex` attested a patch that only one lock wired when the
other lock had no entry for the package at all. npm 12 installs from
package-lock.json and re-resolves a missing entry from the registry,
so the checkout installed unpatched bytes while the VEX document said
`not_affected`.
A twin lock with no entry for the package now contests the wiring the
same way a registry entry does (`patched_ref_unattributable`), in both
directions and for hosted and vendored wiring. A twin that holds the
package only at another version still contests nothing: npm installs
that version, not unpatched bytes of the patched one.
Fixes#798
Assisted-by: Claude Code:claude-opus-5-5
* Make the dual-lock read test use agreeing twins
The test that proves both npm locks are read wired each package in only
one lock. After #798 such a pair is contested (npm re-resolves the
package missing from the other lock), so the fixture now has each lock
wire both packages. It still proves both locks are read (4 refs) and
that the v2 legacy mirror adds nothing.
Refs #798
Assisted-by: Claude Code:claude-opus-5-5
* Keep patch refs out of a vex test's messages
CodeQL flagged the new dual-lock test for printing the wired patch
reference (which holds the patch uuid) in an assertion message. The
message now names the wiring mode instead.
Refs #798
Assisted-by: Claude Code:claude-opus-5-5
* Fix vex alias tests broken by store-copy merge
#605 taught the name-keyed npm resolver to probe bundled store
trees, so it now finds aliased copies (node_modules/lp) and a nested
host's store peers itself. Two vex_consumed tests from #738 assumed
that set never held aliases, so main's CI went red after both merged.
The tests now feed the alias-free set explicitly to keep covering
alias expansion, and also check the resolver's own set reaches the
same copies with no duplicates. No production code changes.
Assisted-by: Claude Code:claude-opus-5-5
(cherry picked from commit 40dac07)
* Contest a twin npm lock that lacks the wired version
A twin lock that held the package only at another version still let the
wired ref through. npm keeps that entry only while it satisfies
package.json, and otherwise fetches the wired version unpatched from the
registry, so the lock alone can't vouch for it. The twin now contests
unless it has an entry for the same name@version at any path. Lock pairs
the rewriters keep in sync share that set, so they are unaffected.
Refs #798
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TtZrsd52E6vxhvF9hpLVSw
---------
Co-authored-by: Claude <noreply@anthropic.com>
0 commit comments