You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 73c2383
Browse filesBrowse the repository at this point in the historyBrowse files
Fix npm linked-store alias copies left unpatched (#852) (#987)
* Start fix for #852
Assisted-by: Claude Code:claude-opus-5-5
* Patch npm linked-store alias copies
With npm 9-11's install-strategy=linked, an alias install such as
"lp": "npm:left-pad@1.3.0" lives in a store entry named after the
alias (node_modules/.store/lp@1.3.0-<hash>/node_modules/lp). Agent
mode only looked for node_modules/left-pad inside store entries, so:
- beside a plain left-pad copy, apply patched only the plain copy and
exited 0, and vex attested not_affected while require('lp') still
loaded unpatched code;
- with only the alias installed, apply reported the package "not
found on disk" and vex refused with package_not_found.
The resolver now searches npm linked-store entries for alias copies
the same way it searches an importer tree. The store variant fan-out
used by apply, rollback and vex also probes a same-version entry under
another name at its own dir. In both cases the entry's package.json
stays the authority on name and version.
Fixes#852
Assisted-by: Claude Code:claude-opus-5-5
* Cover linked-store alias copies in vex
Adds the npm linked-store alias layout from #852 to vex's every-copy
regression: an unpatched alias-named store entry must keep the purl
out of the VEX document, and all copies patched must attest it.
Refs #852
Assisted-by: Claude Code:claude-opus-5-5
* Route Gradle digests through utils::digest
main has failed socket-patch-core's lib tests since Gradle support
(#646) and the digest helpers (#865) both landed. The guard test
production_digests_go_through_the_helpers flags three files #646 added
that still hash inline: crawlers/gradle_cache.rs, patch/jvm_jar.rs and
patch/sidecars/maven.rs. That breaks test, test-release and coverage on
every open PR.
Each inline sha1/sha256 call now goes through sha1_hex_of or
sha256_hex_of, which compute the same lowercase hex. Behaviour is
unchanged.
Assisted-by: Claude Code:claude-opus-5-5
(cherry picked from commit 659ac2c)
---------
Co-authored-by: Claude <noreply@anthropic.com>
0 commit comments