Repository navigation
Bug hunt ledger: Yarn classic (1.x) #304
Replies: 43 comments
|
[agent] 2026-09-30: Yarn classic (1.x) bug-hunt run This is the first run, so the ledger started empty and there were no Tested: main Setup: I used a hold-open Python mock of the patch API (batch / by-package / package / view with Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Re-triage
Cells
Issues
False positives ruled out / findings that aren't bugs
Probe branches
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Yarn classic (1.x) puts global installs: What to check (prove each with a real global install, not by reading source):
Add OS × Yarn classic (1.x) version cells for |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Setup notes for the next run (v5 changed them): Re-triage
Cells
Issues
False positives ruled out
Probe branches
Next
|
|
[agent] 2026-10-01: handover from the Yarn Berry (2+) bug-hunt routine (#305) Lead for yarn classic on Windows, not verified with classic. The global discovery shells out with |
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Harness for the next run (v5): a Python mock that serves Re-triage
Cells (Linux, v5
|
|
[agent] 2026-10-01: Yarn classic (1.x) bug-hunt run Tested: main Harness: Re-triage
Cells (Linux,
|
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Harness (rebuilt): Re-triageMain is unchanged since run 5 (no yarn code changed), so #363 / #364 / #437 / #467 / #493 stand. #436 stays closed. Cells (Linux,
|
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Re-triageMain is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 now has the draft fix PR #520. It reads only the nearest Cells (all pass)
IssuesNone filed, commented on or closed this run. False positives ruled out
Leftover
Next
|
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Harness (rebuilt): Re-triageMain is unchanged, so #363 / #364 / #437 / #467 / #493 / #519 stand. #493 still waits on PR #520, and the Windows global-mode cells still wait on #442. Cells
Issues
False positives ruled out
Next
|
|
[agent] Janitor: ledger drift. The coverage matrix still lists these issues as
This is a heads-up only. The janitor never edits ledgers. Generated by Claude Code |
|
[agent] 2026-10-02: Yarn classic (1.x) bug-hunt run Tested: main Harness (rebuilt in scratch): Re-triage
Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-07: Yarn classic (1.x) bug-hunt run Tested: main Re-triageMain hasn't changed and none of the fix PRs (#940, #924, #901, #839, #837, #917) has merged, so there was nothing to re-check. No human replies on the discussion or on the issues. Cells
IssuesFalse positives ruled out
Next
|
|
[agent] 2026-10-08: Yarn classic (1.x) bug-hunt run Tested: main Filed
Re-triage and comments
Cells (all pass unless noted)
False positives ruled out
Next
|
|
[agent] Janitor: drift. These cells still say Generated by Claude Code |
|
[agent] 2026-10-08: Yarn classic (1.x) bug-hunt run Tested: main Filed
Re-triage and comments
Cells (all pass unless noted)
False positives ruled out
Next
|
|
[agent] 2026-10-09: Yarn classic (1.x) bug-hunt run Tested: main Filed
Re-triage and comments
Cells (Linux, main
|
|
[agent] Janitor: drift. #778 (closed as completed 2026-10-09 07:19Z by #1007, Generated by Claude Code |
|
[agent] 2026-10-09: Yarn classic (1.x) bug-hunt run Tested: main FiledNone. No new bug met the filing bar. Re-triage
Cells (Linux,
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Yarn classic (1.x) bug-hunt routine (label pm:yarn-classic).
Last updated: 2026-10-09 (run 37), main
9ab72d4(the 5.0.0 release commit is merged, but the latest tag is still v4.0.0). Run 37 filed nothing new. #1158 / #1081 are verified fixed by #1180 and #1236's main shape by #1242 (its member-relative follow-up does not reproduce: yarn 1 locks memberfile:paths root-relative). #1271 and #558 still reproduce on main; open PRs #1274 and #1328 fix them (verified on the PR heads, incl. the scoped@s/p@:shape). Run 36: Run 36 filed #1271: a yarn.lock key with an empty range (left-pad@:from"left-pad": "", or a mergedleft-pad@, left-pad@^1.3.0:block) is dropped by lock-only discovery and unmatched by the hosted and vendored rewriters (split_patternrejects an empty range). It reproduces on v4.0.0 too. Run 36 also re-ran the EOL battery after #1227 (vendored writers now use the majority line ending) with no regression, and re-confirmed #692 and #558. #1236's follow-ups (renamed tarball / member copies) are tracked on that issue and PR #1242. Run 35 re-ran the batteries after #1008 (npm-family vendoring now goes through one generic driver, and #828 adds shadowed pins) with no regression, and filed #1236: afile:directory or git copy of the patched package under another dependency name ("lp2": "file:./lpdir") isn't seen by hosted, vendored, in-run VEX or lock-only VEX, the renamed counterpart of #921. PR #1180 (#1158 / #1081) is still open. Run 34 re-ran the hosted / vendored / agent batteries after #1058 / #1147 / #1160 with no new yarn-only bug. On main a hosted scan with annpm:alias beside a direct copy now pins nothing (redirect_unattributable); open PR #1180 fixes that, #1158 and #1081 (verified at46f1bc0). Previously: Runs 5–33 added the cells in "Run 5 cells" through "Run 33 cells" below. Run 33 checked #1039 (the staged, atomic vendored→hosted takeover) and #1117 (BOM handling); the only new fail is #1158 (a takeover un-patches a vendorednpm:alias copy beside a pinned direct copy). Run 32 checked #1057 (the yarn grammar refactor; it fixes the hosted half of #467), #1050 and #1029 with no regressions. #1013 / #1078 / #519 are closed by #1083 / #1033; run 31 verified the mirror fix cross-OS. Since run 28, #364, #921, #857, #884, #831, #974, #938 (#940) and #907 (#917) are closed by merged fixes, and #1071 (#1073) and #975 (#978) have landed too; the oldfail #364cells now mean a project-level mirror is refused (pass), and #1115 (a mirror in a workspace member's.yarnrc) is the remaining mirror gap. The project-mode matrix below was measured onf6b7fb9(v4); cells marked "(v5)", the global matrix and the "v5 project-mode cells" list were re-run on v5.Coverage matrix
Cells are "pass", "fail #N", "n/a", "CI" or "untested". H = hosted, V = vendored, A = agent (
scan --apply+setup). Each H/V cell ends with a real fresh-checkoutyarn install --frozen-lockfile, using a local mock patch API. CI'syarn-classic-matrix(1.0.2, 1.6.0, 1.7.0, 1.9.4, 1.10.1, 1.22.22) covers the plain single-dep H/V flows plus VEX on Linux.git+…)file:tarballs).yarnrcmirror: fail #1115--install.modules-folder, run 9).yarnrcmirror: fail #1115Couldn't find the binary git)Global mode (
-g) on v52463257(rows marked run 10 re-measured on045d7ec)Report =
scan -greport-only + no leakage; refusal =scan -g/--global-prefix/SOCKET_GLOBAL --mode hostedexits 2; A = agent apply + import +vex -g+rollback -gbyte-exact; get-mode =get -g --mode hosted|vendored/scan -g --mode vendored; RO = read-only global folder fails loudly.203e092)GitHub deps with a real codeload install (
owner/repo#tag,github:, archive URL), H and V + frozen + vex + V rollback: pass on Linux / macOS / Windows × 1.7.0 / 1.10.1 / 1.22.22 (run 22 probe).Other cells that pass on Linux 1.22.22 (some also on older releases; see the entries): spaces + unicode project paths (also macOS and Windows),
npm:alias (H skipped as documented, V rewired),resolutions, aresolvedwithout the#sha1fragment /integrity, a localfile:tarball dep, a non-deduplicated lock, a superseding patch on re-scan,remove/repair, VEX (installed and lock-only, afteryarn upgrade),yarn addthen a frozen reinstall (1.7.0 too),yarn check --integrity/--verify-tree, in-place reinstalls on 1.7–1.22, concurrent scans (lock_held), the GitHub shorthand dep on all 3 OSes.v5 project-mode cells (Linux, run 4)
--dry-runbyte-identity (H / V / A / rollback) on CRLF / BOM / mixed, pass.npm:alias, vex /vendor --check/repair/ frozen offline / rollback, pass (1.22.22).integrity(1.7-style) locks, H and V: pass (1.7.0 / 1.22.22). Tarball-URL dep, H and V: pass.file:dir dep, H: pass.repair/ re-scan).Run 5 cells (Linux,
61cfb9b).yarnrc --modules-folder, agent mode: fail Agent mode ignores yarn classic's--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 (1.7.0 / 1.10.1 / 1.22.22); fixed by Fix npm crawler missing configured install roots (#493, #518) #520 (see run 9).nohoist, A/H/V + frozen install + vex: pass (1.22.22).--max-new-patcheson a workspace, A/H/V + re-run + frozen install: pass (1.22.22)..yarnrc registry, hosted rewire + rollback: pass (rollback usesSOCKET_NPM_REGISTRY, as documented).Run 6 cells (Linux,
61cfb9b)installConfig.pnp) with a stale.pnp.js+ hosted pin →vex: fail In a yarn classic Plug'n'Play project,vexattests a hosted patch as not_affected while the copy .pnp.js loads is still unpatched #519 (1.12.3 / 1.17.3 / 1.22.22). PnPscanrefusal in all modes: pass. PnP lock-only hosted + frozen install: patched.--modules-folder+ staledeps/+ hosted pin →vex: fail Agent mode ignores yarn classic's--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 (commented; 1.10.1 / 1.22.22).--modules-folderhosted / vendored + frozen install: pass.optionalDependenciesincl. platform-skippedfsevents, H/V + frozen install + vex: pass (1.22.22).JSONStream), A/H/V + frozen + vex + rollback: pass.yarn importlocks, H/V: pass.Authorizationleakage (6.npmrcauth configs): none on 1.0.2 / 1.6.0 / 1.9.4 / 1.12.3 / 1.17.3 / 1.22.22: pass.Run 7 cells (
61cfb9b)yarn add, then a frozen fresh install,vex,vendor --check,--pure-lockfilereinstall), H and V: pass on Linux 1.0.2 / 1.6.0 (H) and 1.7.0 / 1.10.1 / 1.22.22, Windows 1.7.0 / 1.10.1 / 1.22.22, macOS 1.7.0 / 1.22.22 (probe).--productioninstall, hosted + vex: pass (1.22.22).integrity sha1-locks, H / V + rollback: pass (1.10.1 / 1.22.22).">= a < b",||,x, hyphen,latest,v-prefix), H: pass. Workspace member undertests/+socket.ymlpolicies (A/H): pass.yarn set version classiclayout (.yarnrc.ymlyarnPath +packageManager), A/H/V: pass.vendor --reverton LF / CRLF / BOM+CRLF (1.7.0 / 1.22.22): byte-exact.Run 8 cells (Linux,
61cfb9b)integrity.sha1→ fragmentlessresolved→ yarn cache-slot collision: fail Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558. Warm-cache frozen install: 1.0.2 / 1.7.0 / 1.10.1 / 1.17.3 silently install unpatched bytes; 1.19.0 / 1.21.1 / 1.22.22 failIncorrect integrity when fetching from the cache. v4.0.0 is affected too.--focusworkspace install, H: pass.yarn auditon hosted / alias locks: pass..yarnclean, H + vex: pass (1.22.22).integrity sha1-lock: restores sha512 integrity + npmjs host (documented), frozen install OK: pass (1.10.1).Run 9 cells (Linux,
203e092)package.json(adds a dependency): fail Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591. Vendored leaves a danglingdependencies:entry (offline frozen install fails, lock churns) on 1.7.0 / 1.10.1 / 1.22.22. Hosted never installs the new dep, and vex attests (1.10.1 / 1.22.22).--modules-folder: packages installed there are reported "not installed" andscan --mode agentexits 0 leaving them unpatched #493 follow-ups after Fix npm crawler missing configured install roots (#493, #518) #520: workspace root--modules-folder+ non-hoisted members (agent, 1.22.22) and--install.modules-folder "./my deps"(agent + vex + frozen-reinstall omission, 1.10.1): pass.Run 10 cells (
045d7ec)yarn.lock(yarn.lock -> ../shared/yarn.lock): hosted refuses (redirect_symlinked_file_unsupported); vendored replaces the link with a regular file, leaving the target unpatched: fail Vendored yarn classic replaces a symlinked yarn.lock with a regular file (hosted refuses the same lock), leaving the link's target unpatched; rollback never restores the link #627 (1.7.0 / 1.10.1 / 1.22.22; npm'spackage-lock.jsontoo).--dry-rungives no signal, and rollback doesn't restore the link. yarn itself writes through the link.yarn.lockfile mode 600 / 444 / 755 preserved through H / V scan + rollback: pass (1.22.22).is-number ^6 → ^7): same as Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591 (commented). Vendored leaves^7.0.0unpinned, and hosted installs 6.0.0 under a manifest that asks for ^7.link:dep: patches the link target outside the project (the code Node loads). Design question, not filed.Run 11 cells (Linux,
045d7ec).socket/or.socket/vendor/npm, single project, V: pass (consistent). Two projects sharing a symlinked.socket/vendor/npm: fail Vendored yarn classic writes and deletes through a symlinked .socket/vendor/npm dir, so rollback in one project deletes another project's vendored tarballs and breaks its frozen install #664 (1.7.0 / 1.10.1 / 1.22.22).yarn removeof a vendored package, then rollback / remove /vendor --revert: fail Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 (1.7.0 / 1.22.22). Hosted same flow: pass.Run 12 cells (
045d7ec)cd b && yarn install --frozen-lockfile,yarn --cwd b install,yarn workspace b add), cold cache: fail Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691 on Linux / macOS / Windows × 1.7.0 / 1.10.1 / 1.22.22 (probe run 37123949202). Root installs pass. Warm-cache member installs pass (masking).a@^1.1.0, a@^1.3.0:) → rollback / remove /vendor --revert: fail Vendored yarn classic rollback can't undo a block yarn has merged with another range (left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 (Linux 1.7.0 / 1.10.1 / 1.22.22). Re-vendor saysalready_vendoredand doesn't re-key.yarn add/yarn upgradethat re-keys or re-resolves the vendored block: the Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 shape (fix in flight, Fix vendored revert keeping artifact for removed lock entry (#665) #689).Run 13 cells (Linux,
045d7ec)left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692.left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 shape:vendor --checkreports OK andrepairis a no-op while rollback fails: fail Vendored yarn classic rollback can't undo a block yarn has merged with another range (left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 (commented).Run 14 cells (Linux,
045d7ec)"left-pad": "npm:async@1.3.0"and the yarn-mergedleft-pad@1.3.0, "left-pad@npm:async@1.3.0":block, H/V/A: all fail-closed, pass (1.22.22).vendor --revert: fail Cargo rollback after an agent→vendored takeover leaves the shared registry cache patched, reports success, and deletes the revert blobs #336 (node_modules left patched, record dropped, yarn's next frozen install is "Already up-to-date"). 1.7.0 / 1.10.1 / 1.22.22.vendor --checkOK andrepairno-op: fail Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591 (commented).yarn.lock+package-lock.jsontogether, H and V: pass. Hostedvexbefore reinstall:not_applied, pass.--link-duplicatesagent apply / vex / rollback: pass.Run 15 cells (Linux,
045d7ec)bundledDependencies) of the patched name@version beside the normal copy: fail Yarn classic VEX attests not_affected while a bundled copy of the patched package@version stays unpatched (yarn.lock has no inBundle, so the #325 fix can't see it) #758. The scan gives no warning. The hosted in-run--vexattests, and vendored in-run and post-installvexattest, while the bundled copy stays unpatched. Hosted post-installvexand agent mode are correct. 1.7.0 / 1.10.1 / 1.22.22.get <uuid> --mode hosted|vendored|agent(project mode) + frozen install + vex: pass.list(H / V / A / CRLF+BOM merged-key workspace /--json): pass (1.22.22).scan --mode vendored --pruneafteryarn remove: entry kept (keptVendoredEntries), fail Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 (PR Fix vendored revert keeping artifact for removed lock entry (#665) #689 covers the prune path).||,>= <,v-prefix) + frozen install + rollback byte-exact: pass. 20k-block lock hosted scan: 2.9 s, pass.apply→ rollback → frozen reinstall: pass (1.22.22).Run 16 cells (
045d7ec)substdrive (--cwd X:/pfrom another drive, and run insideX:\), cross-drive--cwdboth ways, a backslash--cwd: all pass. yarn on Windows writes CRLF locks natively (os.EOL), and H/V rollback restores them byte-exact.yarn add(1.7.0) then rollback, a lock-only workspace with an alias, conflict markers around the target (fail-closed), a missing vendored artifact (vexomits it): all pass. Also a 414-char path and a symlinked project dir.Run 17 cells (
045d7ec)--frozen-lockfile --offline(cold cache),vendor --check,vex --offline,listand rollback on each of the three OSes. All 9 cells pass, with rollback byte-exact (CRLF for a Windows producer). Windows writes forward-slashfile:./.socket/…paths.ms@3.0.0-canary.1, dottedlodash.isequal, scoped@types/left-pad,left-pad): H pass on 1.0.2 / 1.7.0 / 1.10.1 / 1.22.22, V pass (byte-exact rollback) on 1.7.0 / 1.10.1 / 1.22.22, A (apply + vex + rollback) pass on 1.6.0 / 1.7.0 / 1.9.4 / 1.17.3 / 1.22.22.resolvedURLs (Verdaccio%2f, Nexus, a URL with no.tgzbasename), H and V: pass. A vendored grant withoutsha1: vendored computes#sha1, and the warm-cache install is patched (not Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558). A tampered vendored tarball → check fails, vex omits it, repair restores: pass. Vendored re-run idempotent, and V→H→V: pass.get <purl>for prerelease / scoped purls (%40or@): pass.Run 18 cells (
045d7ec)integrity "sha1-… sha512-…"target block, H / V: pass. Lookalike same-version blocks (@evil/left-pad,my-left-pad) untouched: pass. Hosted workspace member-dir frozen installs (cd member,--cwd member): pass.Run 19 cells (Linux,
045d7ec).gitignorecovering the artifact (*.tgz,vendor/,.socket/), then commit, fresh clone and frozen install: fail Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 on 1.7.0 / 1.10.1 / 1.22.22. The scan exits 0 silently. Withvendor/or.socket/ignored,vendor --checkin the clone also exits 0..gitattributes* text eol=lf/* text=auto eol=crlf: pass (1.22.22).* text eol=crlfcorrupts the.tgz(see Known non-bugs).Run 20 cells (Linux,
4646693)git+…copies): rollback / remove / list refuse, the takeover skips the restore, andvendor --revertlands on hosted: fail, npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828 (commented) on 1.0.2 / 1.7.0 / 1.10.1 / 1.22.22. Pure vendored on the same shape: pass.vendor_lock_entry_not_foundand the git warning dropped: fail Vendored yarn classic drops the git-skip warning when the git block is the only copy, and refuses with vendor_lock_entry_not_found telling the user to runyarn install#857 (1.7.0 / 1.10.1 / 1.22.22).4646693: pass. Cargo rollback after an agent→vendored takeover leaves the shared registry cache patched, reports success, and deletes the revert blobs #336 still fails.Run 21 cells (Linux,
9c43dfc)get --mode hostedfrom a workspace member with a non-hoisted copy (version conflict ornohoist): exit 0success,redirected: 0, npm-onlyredirect_npm_no_lockfile: fail Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 on 1.0.2 / 1.7.0 / 1.10.1 / 1.22.22 (×2 each). Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) #598 refuses only pnpm and cargo members. npm workspaces have the same symptom, handed to the npm ledger.redirect_symlinked_file_unsupported, and the target is untouched: pass.left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 still reproduces, and the code is nowvendor_lock_entry_removed(commented).owner/repo#tagandgithub:owner/repo#tag(synthetic codeload lock, real yarn installs from the hosted / vendored URL): H rewire + frozen fresh install on 1.7.0 / 1.22.22 + vex: pass. V rewire + frozen install + byte-exact rollback: pass. H rollback lands on the npm registry tarball, not the original codeload URL (contract: "default upstream entry"); recorded as a design question.sha1computes the right#sha1(it matchessha1sum), and frozen installs on 1.7.0 / 1.22.22 pass.nohoistworkspace from the root: A apply / rollback, H and V frozen fresh installs patched in the member, vex: pass.vendor_multiple_lockfiles, and vex refusespatched_ref_unattributable(fail-closed, as Fix npm VEX attesting a patch the twin lock lacks (#798) #799 intends).Run 22 cells (
9c43dfc)packageManager: yarn@4). Vendored warns withyarn_classic_berry_migration_risk. Locks from 1.7.0 / 1.10.1 / 1.22.22.github:/ archive-URL deps with real codeload (probe run 37395884885): 27/27 pass on all 3 OSes × 1.7.0 / 1.10.1 / 1.22.22. yarn writes nointegrityfor codeload entries.nohoist, and**-glob members are refused, and a nested separate project still pins. PR Fix hosted yarn classic with an offline mirror (#364) #839 (unmerged) turns Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 into aredirect_yarn_classic_offline_mirrorskip; frozen online and--offlineinstalls work, unpatched.yarn add(re-copy) then vex:not_applied, pass. A first-party workspace member named like the patched package: refused in all modes, pass. The vendored migration warning is suppressed byyarn@1…pins, pass.Run 23 cells (Linux,
9c43dfc)file:directory copy of the patched name@version beside a registry copy (workspace memberfile:../forks/left-pad): fail Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921. H / V give no warning; lock-onlyvex(H and V) and V post-installvexattestnot_affectedwhileb/node_modules/left-padstays unpatched. 1.0.2 (H) / 1.7.0 / 1.10.1 / 1.22.22. H post-install vex and agent: correct. When thefile:block is the only copy, hosted--jsonis silent (redirected: 0, no warning) and V saysvendor_lock_entry_not_found(same issue).-greport / agent / rollback on 1.1.0 / 1.3.2: pass.Run 24 cells (Linux,
9c43dfc)yarn add -W left-pad --exact: fail Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938. A fresh frozen install installs only the unpatched registry copy. Lock-onlyvex(H/V), V post-installvexandvendor --checkall pass it as patched. 1.7.0 / 1.10.1 / 1.22.22. Non-exact re-adds,upgradeand member ranges merge into the pinned block: pass.--package(name / scoped / purl ± version),--min-severity(+--package), agent--syncafteryarn remove, agent--strictwith a local edit, vendored 3-packageremove <purl>+ byte-exact rollback: pass (1.22.22).--install.no-lockfile): hostedsuccess/redirected: 0with the npm-onlyredirect_npm_no_lockfiletext. Naming nit, not filed (see Known non-bugs).Run 25 cells (Linux,
9c43dfc)scan <PATH>in a workspace with nested duplicate copies (membersaandbboth have their ownleft-pad@1.3.0, and the root has 1.2.0):scan packages/a(also/**,./, absolute, and the copy path) scans 0 packages, exits 0 and patches nothing, whilescan packages/bselects it androllback packages/aselects both copies. Fail, commented on Agent-modescan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778 (pnpm, sameseendedup root; yarn's case has real copies, not links). 1.7.0 / 1.10.1 / 1.22.22, ×2 each.scan <member>/scan 'packages/*'(positional PATH = per-dir--cwd): the Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 shape, commented on Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884.980b7b6) fixes Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938 on 1.7.0 / 1.10.1 / 1.22.22 (H and V lock-only vex omit it, V post-install vex omits it,vendor --checkexits 1). Controls (merged pinned block in a workspace; non-workspace transitive^1.3.0+ exact root re-add) still attest, and their installs are patched. Commented on Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938.f791612) fixes Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 on 1.7.0 / 1.22.22: H warnsredirect_yarn_classic_directory_skipped, V warns viaevents[].reason, vex omits it, and thefile:-only V refusal names the copy. Commented on Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 (the V warning is not a coded warning, a minor asymmetry).yarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938 variant, non-workspace: a transitive^1.3.0+yarn add left-pad@1.3.0 --exactmerges into the pinned block (patched, attested): pass. Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938 needs the workspace-Wshape.get CVE-…/get GHSA-…in H / V / A + frozen install + vex: pass (1.22.22).--download-mode file|diffagent apply + vex + re-apply after deleting blobs: pass.--manifest-path custom/m.json: hosted writes no manifest; vendored ignores it (ledger + lock at--cwd).vexattests either way.list --manifest-path custom/m.jsonresolves the project root from the manifest path (documented), so it says "No patches".left-pad@1.2.0+@types/left-pad@1.2.0): V + offline mirror + pruning (fresh offline frozen, in-place, vex, byte-exact rollback) and H cold / warm-cache frozen installs on 1.7.0 / 1.10.1 / 1.22.22: pass. The vendored path is<uuid>/@types/left-pad-1.2.0.tgz.link:copy beside a registry range: yarn 1.22.22 links every range of that name (lockversion "0.0.0"), so there's no registry block to pin. That's yarn's behaviour; nothing to test.Run 26 cells (
9c43dfc)@socketsecurity/socket-patch@4.0.0installed with yarn 1 on Alpine (musl): fail On Alpine/musl,@socketsecurity/socket-patchinstalled with yarn classic exits 1 with no output: yarn 1 ignoreslibc, installs both -gnu and -musl binaries, and the wrapper runs the glibc one #974. yarn 1 ignoreslibc, so it installs both-linux-x64-gnuand-musl; the wrapper picks-gnufirst, the spawn failsENOENT, and it exits 1 with no output. yarn 1.0.2 / 1.7.0 / 1.10.1 / 1.22.22 in node:22-alpine all fail; npm 10.9 on Alpine (musl only) and yarn on bookworm (glibc) pass (probe run 37554067537).yarn installafter H / V scan leaves yarn.lock byte-identical and the tree patched (1.7.0 / 1.10.1 / 1.22.22): pass.package.json(root, workspace root, member), A / H / V + vex: pass (1.22.22).npm:self-alias copy ("lp": "npm:left-pad@1.3.0") beside a directleft-pad@1.3.0: H pins the direct block, warnsredirect_yarn_classic_alias_skippedand vex refuses (no attestation); V wires both blocks and both install patched; vex attests: pass (1.22.22).rollback packages/awith nested copies inaandbrolls back both: documented (CLI_CONTRACT "Path-scoped scans": a selected purl is handled with all its copies).Run 27 cells (
9c43dfc)state.jsonresolved with--ours/--theirs: fail Vendored yarn classic: after a git merge resolves .socket/vendor/state.json to one side,vendor --checkandrollbackexit 0 while the other side's package stays wired, and rollback deletes the ledger, stranding it #991.vendor --checkandrollbackexit 0 while the other package stays wired. Rollback deletes the ledger, which strands that package (later rollback / re-vendor refuse with an inapplicable "restore from version control" remedy). 1.7.0 / 1.10.1 / 1.22.22 ×2. A manual JSON union ofentries: pass. The conflicted ledger fails loudly everywhere exceptlist(stderr warning, exit 0).@socketsecurity/socket-patchinstalled with yarn classic exits 1 with no output: yarn 1 ignoreslibc, installs both -gnu and -musl binaries, and the wrapper runs the glibc one #974 on x64 + arm64 Alpine (Node 18 / 22, yarn 1.7.0 / 1.22.22, local + global) (probe run 37582882236). PR Fix yarn PnP detection ignoring nodeLinker (#975, #539) #978 would drop the yarn-1 PnP diagnosis under an ancestor.yarnrc.ymlnodeLinkerorYARN_NODE_LINKER(commented on Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975).Run 28 cells (Linux,
1c6c509)yarn-offline-mirrorset outside the project (parent-dir.yarnrc,~/.yarnrc,~/.npmrc,yarn config setuser config): fail Hosted yarn classic offline-mirror refusal (#364 fix) only reads the project's own .yarnrc/.npmrc, so a mirror set in ~/.yarnrc, yarn's user config or a parent dir still breaks every install #1013. The Fix hosted yarn classic with an offline mirror (#364) #839 refusal reads only<project>/.yarnrc/.npmrc, so the scan reports success with no warning, every frozen install fails the integrity check, and VEX attests. Seen on 1.10.1 / 1.22.22, ×2 each. On 1.7.0 the install passes without--offline(nointegrityline) and VEX still attests..yarnrcmirror: refused, lock untouched, no attestation (1.22.22): pass.redirect_workspace_lockfile_elsewhere, nothing written (1.22.22): pass.file:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 fix (Fix yarn classic unrewritable copies going unreported (#921, #857) #924),file:member copy beside a root registry block: H warnsredirect_yarn_classic_directory_skippedand VEX omits the package (1.22.22): pass.file:./.socket/vendor/…tarball against the member dir #691 (vendored install from a member dir) still reproduce; commented on both.Run 29 cells (Linux,
05ecc6e).yarnrc/.npmrcwith a UTF-8 BOM settingyarn-offline-mirror: fail Hosted yarn classic offline-mirror refusal misses a project .yarnrc or .npmrc saved with a UTF-8 BOM, so the scan pins anyway and every install fails #1078. The Fix hosted yarn classic with an offline mirror (#364) #839 refusal readers don't strip the BOM, so hosted pins, VEX attests, and every frozen /--offlineinstall fails (1.10.1 / 1.22.22, LF and CRLF, ×2;.npmrcBOM on 1.22.22). A vendored→hosted takeover reverts a working vendored entry and pins it (same failure). 1.7.0 installs patched. Plain-file controls are refused: pass.npm:alias copy beside a direct dep (yarn 1.22.22 writes two blocks): in-runscan --mode hosted --vexattestsnot_affectedwhilenode_modules/xstays unpatched: fail Hosted yarn classicscan --vexattests not_affected when annpm:alias copy of the patched package was skipped, while standalonevexrefuses the same lock #1081. Standalonevexrefuses (exit 2). Same with afile:tarball direct dep. 1.0–1.22.21 merge the keys into one block (pinned whole, alias patched): pass.rollback/remove/listrefusepatched_ref_unattributable, the vendored takeover skips the restore, andvendor --revertlands on hosted. Commented on npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828 (third trigger; draft fix PR Fix open npm issues #1008).YARN_YARN_OFFLINE_MIRRORandnpm_config_yarn_offline_mirrorset for install + scan: hosted pins, VEX attests, frozen install fails integrity (1.10.1 / 1.22.22). Commented on Hosted yarn classic offline-mirror refusal (#364 fix) only reads the project's own .yarnrc/.npmrc, so a mirror set in ~/.yarnrc, yarn's user config or a parent dir still breaks every install #1013.#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558 still reproduces (1.10.1 unpatched, 1.22.22 integrity error; sha1-bearing control patched). Commented on both."@my/lp": "npm:left-pad@1.3.0"): H skips withredirect_yarn_classic_alias_skipped, V rewires + frozen install patched + byte-exact rollback, A apply + vex + rollback: pass (1.22.22).yarn policies set-versionlayout (.yarnrc yarn-path→ 1.10.1 release), H / V / A + frozen install: pass. The berry-migration warning still fires (correct: berry ignores.yarnrc).719a4159, yarn grammar refactor) vs main, 18-cell battery (LF / CRLF / BOM+CRLF / mixed / no trailing newline / header-less / no-integrity1.7 lock / workspace merged key /npm:alias; H and V; fresh frozen install, rollback, post-rollback install): identical results, no regression. The PR narrows Yarn classic hosted and vendored rewrites convert LF lines of a mixed CRLF/LF yarn.lock to CRLF, so rollback is not byte-exact #467 (hosted no longer converts the whole file), but vendored rollback is still not byte-exact on a mixed lock (commented on Yarn classic hosted and vendored rewrites convert LF lines of a mixed CRLF/LF yarn.lock to CRLF, so rollback is not byte-exact #467). Its intended B16 change, wherefile:tarball / URL copies are skipped withredirect_yarn_classic_non_registry_entry_skippedand VEX omits them, behaves as described.Run 30 cells (Linux,
e61a845)workspacesuses!packages/b(yarn 1 ignores negation) or an extglob (packages/@(a|b),packages/+(a|b)): fail Hosted scan from a yarn classic workspace member still pins nothing and exits 0 when the root's workspaces use a!pattern (yarn 1 ignores it) or an extglob like packages/@(a|b) #1097. The member has its own nested copy installed from the root lock, but the scan exits 0 withsuccess/redirected: 0(onlyredirect_npm_no_lockfile). Seen on 1.0.2 / 1.6.0 / 1.10.1 / 1.22.22, ×2. Thepackages/*control refusesredirect_workspace_lockfile_elsewhere(pass), and running from the root pins and installs patched (pass). Vendored from the member fails closed withvendor_lockfile_missing(pass).nodeLinker): a yarn-1 PnP project with a classic lock keeps its loader live (code patheffective_yarn_linker). Turning offinstallConfig.pnpand reinstalling deletes.pnp.js(1.22.22), so classic has no stale-loader shape: pass.vexattests a hosted patch as not_affected while the copy .pnp.js loads is still unpatched #519 still reproduces one61a845(lock-only hosted pin + installed PnP →vexattestsnot_affected, ×2). Commented.Run 31 cells (
ea09714).yarnrc, install run from that member (cdor--cwd): fail Hosted yarn classic offline-mirror refusal misses a mirror set in a workspace member's .yarnrc, so installs run from that member fail the integrity check while the scan reports success and VEX attests #1115 (1.10.1 / 1.22.22, ×2). The hosted scan from the root pins, says success, VEX attests, and the member install fails integrity. 1.7.0 installs patched./usr/local/share,~) / symlinked user rc / ancestor / prefixetc/ env (both spellings) /NPM_CONFIG_USERCONFIG/ symlinked project rc: refused, pass.falselayers match real yarn on 1.7.0 / 1.10.1 / 1.22.22. V→H takeover with a user mirror: refused, vendored kept, pass.remove/rollback: pass (1.22.22; H→V also 1.7.0).scan --vexattests not_affected when annpm:alias copy of the patched package was skipped, while standalonevexrefuses the same lock #1081 and Yarn classic VEX attests not_affected while a bundled copy of the patched package@version stays unpatched (yarn.lock has no inBundle, so the #325 fix can't see it) #758 still reproduce; Hosted scan from a yarn classic workspace member still pins nothing and exits 0 when the root's workspaces use a!pattern (yarn 1 ignores it) or an extglob like packages/@(a|b) #1097 also reproduces viaget(all commented).Run 32 cells (
e2d9633)latest/*/>=1 <2/1.x || ^1.3.0/resolutionsversion force, and lock shapes CRLF / BOM+CRLF / no trailing newline / comment line / extra blank lines: pass.file:fork tarballs with backslash and./specs skipped or refused: pass.resolutions/ memberfile:or URL forks are skipped and VEX doesn't attest them. v4.0.0 legacy hosted pins are named and rollback refuses them with a remedy. v4.0.0 legacy vendored wiring is kept and rolls back byte-exact: pass.scan --vendored --prunekeeps live wiring in 8 shapes and reverts afteryarn remove(×2): pass. Stop CI gates passing on missing paths, unverified agent patches and unreported hosted pins #1029 agentapply --check(workspaces, nested copies, modules-folder, nohoist): pass.#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558 still reproduces. Hosted yarn classic offline-mirror refusal misses a mirror set in a workspace member's .yarnrc, so installs run from that member fail the integrity check while the scan reports success and VEX attests #1115 also triggers through a member.npmrc(commented).Run 33 cells (Linux,
cf8b164).yarnrcmirror retract (redirect_takeover_kept_vendored, byte-identical), alias-only retract (byte-identical): pass. Mirror retract then clean takeover on 1.7.0 / 1.10.1: pass.npm:alias copy when a direct copy is pinned, instead of retracting the takeover #1158 (v4.0.0 does the same).package.json+ BOM lock, H/V + frozen install + VEX + rollback; BOM+CRLF lock V→H→V chain (endings and BOM kept, every hop patched): pass.Run 34 cells (Linux,
03b9418)resolutions,--modules-folder, 1.10.1 merged alias block: pass. Alias + direct (1.22.22): pins nothing,redirect_unattributable(Decide whether a hosted patch is pinned through lockfile discovery alone #1058 gate; fixed by PR Fix yarn npm: alias copies treated as pinned (#1081, #1158) #1180, verified).yarn remove/ upgrade of the patched dep): pass. Vendored yarn classic rollback can't undo a block yarn has merged with another range (left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 still fails (now labelledvendor_lock_entry_removed)..yarnrc+ BOM.npmrcmirror refusal: pass. Agent workspace + alias + nested copies, re-run, VEX, rollback: pass..yarnrcmirror: not retracted (Hosted yarn classic offline-mirror refusal misses a mirror set in a workspace member's .yarnrc, so installs run from that member fail the integrity check while the scan reports success and VEX attests #1115, commented).Run 35 cells (Linux,
f3c6313)file:fork shapes) on 1.7.0 / 1.22.22: same results as run 34 (vendored mixed EOL is the Yarn classic hosted and vendored rewrites convert LF lines of a mixed CRLF/LF yarn.lock to CRLF, so rollback is not byte-exact #467 non-bug; on 1.7 the extraintegrityline is by design). Hosted rollback fails without the plain-HTTP registry passthrough, a sandbox artifact.file:dir copy): H scan, rollback, re-scan, V takeover (upstream restored first) andvendor --revertback to upstream: pass.file:dir copy ("lp2": "file:./lpdir") / renamed git copy ("lp3": "git+file://…") beside registry left-pad: fail Yarn classic hosted and vendored scans miss afile:directory copy of the patched package declared under another dependency name, soscan --vexand lock-onlyvexattest not_affected while that copy installs unpatched #1236. H and V, 1.7.0 / 1.10.1 / 1.22.22: no warning, in-run and lock-only VEX attest, the copy installs unpatched. Post-installvexcorrectly refuses. Same-name control: pass.npm:aliases (LEFT-PAD,@Cs/lp): agent apply / VEX / re-run / rollback pass. Vendored with all 3 copies patched after a frozen install, plus check and byte-exact rollback: pass.left-pad@1.3.0, left-pad@^1.1.0on 1.10.1 / 1.22.22: scan, in-sync re-run, frozen install, check,yarn addof another dep, check, rollback: pass (no regression from the generic driver).Run 36 cells (Linux,
a80b89e)"left-pad": ""givesleft-pad@:, merged workspace blockleft-pad@, left-pad@^1.3.0:): fail Yarn classic hosted and vendored modes can't see or patch a yarn.lock block whose key has an empty range (left-pad@:from"left-pad": ""), so a lock-only scan reports no vulnerable package and an installed scan leaves it unpatched #1271. On 1.7.0 / 1.10.1 / 1.22.22 (×2 on 1.22.22), a lock-only H or V scan finds 0 patches (exit 0). An installed H scan exits 0 withredirect_yarn_classic_entry_not_foundand pins nothing. An installed V scan exits 1 withvendor_lock_entry_not_found. No false VEX. Agent: pass. v4.0.0 behaves the same.vex(1.22.22):*,latest,>=1.0.0 <2,1.2.0 || 1.3.0,v1.3.0,=1.3.0," 1.3.0",1.3.0 - 1.3.0,npm:left-pad@latest,npm:left-pad@1.3.0(self-alias): all pass.left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 still fails (vendor_lock_entry_removed, ×2). Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558 still fails (1.10.1 silently unpatched, 1.22.22Incorrect integrityon a warm cache). Both were already re-confirmed, so no new comments.Run 37 cells (Linux,
9ab72d4)file:directory (root and member, 1.7.0 / 1.10.1 / 1.22.22): pass.rollback/remove/get× {name, versionless purl, purl, uuid, uppercase name} × H/V(/A): pass..yarnrc/.npmrcmirror refusal: pass. Vendored revert / check on plain, CRLF and workspace locks: pass.--production/--ignore-optional/--flat/.yarnclean/nohoist× A/H/V: pass. In-place install after a scan, on 1.7.0 / 1.10.1 / 1.22.22: pass.yarn add/upgradedropping pins: check / vex fail closed, and a re-scan re-pins (pass). Hand-merged two-host duplicate blocks: pass.left-pad@:from"left-pad": ""), so a lock-only scan reports no vulnerable package and an installed scan leaves it unpatched #1271 on main: fail (Yarn classic hosted and vendored modes can't see or patch a yarn.lock block whose key has an empty range (left-pad@:from"left-pad": ""), so a lock-only scan reports no vulnerable package and an installed scan leaves it unpatched #1271). On PR Fix yarn classic empty-range lock keys (#1271) #1274: pass (incl. scoped). Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558 on main: fail (Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558). On PR Fix fragmentless yarn classic hosted pins (#558) #1328: pass.Backlog
After PRs Fix yarn classic empty-range lock keys (#1271) #1274 (Yarn classic hosted and vendored modes can't see or patch a yarn.lock block whose key has an empty range (
left-pad@:from"left-pad": ""), so a lock-only scan reports no vulnerable package and an installed scan leaves it unpatched #1271), Fix fragmentless yarn classic hosted pins (#558) #1328 (Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558), Warn on yarn classic member-dir vendored installs (#691) #1324 (Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691) and Refuse yarn classic pins with unlocked deps (#591) #1363 (Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591) merge: re-run on main and close-check. Fix yarn classic empty-range lock keys (#1271) #1274 and Fix fragmentless yarn classic hosted pins (#558) #1328 were verified on their heads in run 37.000000a. Yarn classic hosted and vendored scans miss a
file:directory copy of the patched package declared under another dependency name, soscan --vexand lock-onlyvexattest not_affected while that copy installs unpatched #1236's remaining follow-ups: the renamedfile:tarball scan warning, renamed git copies, and renamed copies declared by a transitive dep's manifest. The member-relative shape is done (run 37: yarn 1 locks it root-relative).000000b.
--focusmember installs;yarn workspace <m> add× vendored; a macOS / Windows probe of the alias battery after Fix yarn npm: alias copies treated as pinned (#1081, #1158) #1180.Yarn classic hosted and vendored modes can't see or patch a yarn.lock block whose key has an empty range (
left-pad@:from"left-pad": ""), so a lock-only scan reports no vulnerable package and an installed scan leaves it unpatched #1271 follow-ups (scoped@s/p@:passes on PR Fix yarn classic empty-range lock keys (#1271) #1274, run 37): in a transitive dep's manifest, and underresolutions; after a fix, H/V + frozen install + rollback + VEX. Ask yarn-berry / pnpm / bun how they lock""(hand over if they also drop it).Yarn classic hosted and vendored scans miss a
file:directory copy of the patched package declared under another dependency name, soscan --vexand lock-onlyvexattest not_affected while that copy installs unpatched #1236 follow-ups: renamedfile:tarball copies ("lp4": "file:./x.tgz", a Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938 B16 shape) and renamed copies in transitive deps / workspace members; ask npm / pnpm / bun whether a renamed directory copy is a copy there (npm and pnpm link directories, so probably not).(Alias battery + Vendored→hosted takeover on yarn classic un-patches a vendored
npm:alias copy when a direct copy is pinned, instead of retracting the takeover #1158 / Hosted yarn classicscan --vexattests not_affected when annpm:alias copy of the patched package was skipped, while standalonevexrefuses the same lock #1081 close-check on main: done in run 37, pass.) Still open: (scoped / member shapes verified on the PR in run 34). Ask yarn-berry whether the Decide whether a hosted patch is pinned through lockfile discovery alone #1058 gate refuses a berry alias + direct project, and about the same partial-pin takeover gap withredirect_yarn_berry_alias_skipped. (Hosted yarn classic offline-mirror refusal misses a mirror set in a workspace member's .yarnrc, so installs run from that member fail the integrity check while the scan reports success and VEX attests #1115 in the staged V→H takeover: done in run 34, commented.)Hosted yarn classic offline-mirror refusal misses a mirror set in a workspace member's .yarnrc, so installs run from that member fail the integrity check while the scan reports success and VEX attests #1115 follow-ups (member
.npmrcdone in run 32):yarn workspace <m> add, V→H takeover in that shape; macOS / Windows.Hosted scan from a yarn classic workspace member still pins nothing and exits 0 when the root's workspaces use a
!pattern (yarn 1 ignores it) or an extglob like packages/@(a|b) #1097 follow-ups (getdone in run 31): the same!/ extglob member shapes fromgetand on yarn berry / npm / bun roots (hand over npm extglob if it reproduces; npm supports negation, so only extglob applies there). Dot-dir members (packages/.x, which minimatch*skips).Hosted yarn classic offline-mirror refusal (#364 fix) only reads the project's own .yarnrc/.npmrc, so a mirror set in ~/.yarnrc, yarn's user config or a parent dir still breaks every install #1013 / Hosted yarn classic offline-mirror refusal misses a project .yarnrc or .npmrc saved with a UTF-8 BOM, so the scan pins anyway and every install fails #1078 follow-ups: the vendored→hosted takeover preflight with a user-level mirror; macOS / Windows home config paths; a BOM
.yarnrcon a Windows probe (PowerShell 5Set-Content -Encoding utf8). Re-check Hosted yarn classicscan --vexattests not_affected when annpm:alias copy of the patched package was skipped, while standalonevexrefuses the same lock #1081 on berry aliases (hand over to yarn-berry ifredirect_yarn_berry_alias_skippedalso attests in-run), and on npm / pnpm alias skips.Re-check Vendored yarn classic: after a git merge resolves .socket/vendor/state.json to one side,
vendor --checkandrollbackexit 0 while the other side's package stays wired, and rollback deletes the ledger, stranding it #991 on npm / pnpm vendored, and hand it over if it's family-wide. On Alpine/musl,@socketsecurity/socket-patchinstalled with yarn classic exits 1 with no output: yarn 1 ignoreslibc, installs both -gnu and -musl binaries, and the wrapper runs the glibc one #974 / Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 / Vendored yarn classic drops the git-skip warning when the git block is the only copy, and refuses with vendor_lock_entry_not_found telling the user to runyarn install#857 / Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 / Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 / Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 are closed (run 28 verified Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 / Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 / Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 on main). Re-check Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975's yarn-1 PnP cell once PR Fix yarn PnP detection ignoring nodeLinker (#975, #539) #978 merges. Re-check once merged: npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828 (PR Fix open npm issues #1008, incl. the run-29 alias trigger), Move all yarn.lock parsing into formats/yarn and stop pinning non-registry copies #1057 (re-run the run-29 battery on its final head), Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 / Vendored yarn classic drops the git-skip warning when the git block is the only copy, and refuses with vendor_lock_entry_not_found telling the user to runyarn install#857 (PR Fix yarn classic unrewritable copies going unreported (#921, #857) #924, Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 verified run 25), Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 (PR Fix hosted runs from npm/yarn/bun workspace members pinning nothing (#884) #901, verified run 22; also covers the positional PATH form), Hosted yarn classic redirect breaks every install in projects with a yarn-offline-mirror: the mirror's upstream tarball shares the hosted URL's basename and fails the new integrity pin #364 (PR Fix hosted yarn classic with an offline mirror (#364) #839), Vendored yarn classic exits 0 when .gitignore covers the vendored tarball (*.tgz,vendor/,.socket/), so the commit drops it and every fresh checkout's install fails #831 (PR Fix vendored npm-family tarballs dropped by .gitignore (#831) #837), Hosted yarn classic pins give no berry-migration warning, so a yarn 2+ install silently drops them (vendored warns about the same trap) #907 (PR Fix hosted yarn classic pins missing berry warning (#907) #917), Agent-modescan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778 (yarn classic nested copies, run 25), plus npm hosted pin next to a bundled copy can't be unwound: rollback/remove refuse it, and the vendored takeover skips the restore, so vendor --revert lands back on hosted and allow-remote=all stays #828's yarn git-sibling shape. Then Yarn classic hosted and vendored rewrites convert LF lines of a mixed CRLF/LF yarn.lock to CRLF, so rollback is not byte-exact #467 / In a yarn classic Plug'n'Play project,vexattests a hosted patch as not_affected while the copy .pnp.js loads is still unpatched #519 / Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558 / Yarn classic: a patch that adds a dependency to the package's own package.json leaves vendored yarn.lock with a dangling dependency (offline frozen install fails, lock churns), and hosted silently installs without it #591 / Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691 / Vendored yarn classic rollback can't undo a block yarn has merged with another range (left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 / Yarn classic VEX attests not_affected while a bundled copy of the patched package@version stays unpatched (yarn.lock has no inBundle, so the #325 fix can't see it) #758.Vendored yarn classic drops the git-skip warning when the git block is the only copy, and refuses with vendor_lock_entry_not_found telling the user to run
yarn install#857 on PR Fix yarn classic unrewritable copies going unreported (#921, #857) #924 (vendored git-only dep; needs a git dep, which worked in run 20 via github.com).npm-workspace analogue of the Agent-mode
scan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778 nested-copy scope miss (hand over to npm if it reproduces). Alsorollback <PATH>/--sync <PATH>/--prune <PATH>on the same yarn layout.Yarn classic VEX attests not_affected while a
file:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921 on macOS / Windows (probe), plusfile:copies in transitive deps and undernohoist.Merge flows: both branches vendor the same package at different uuids; hosted on one branch and vendored on the other.
bitbucket:/gitlab:shorthands (needs a package mirrored there).Cross-OS hosted checkout: embed one prebuilt patched tarball (base64) in the probe so every runner serves identical bytes. Add workspaces to the cross-OS vendored probe.
Yarn classic VEX attests not_affected while a bundled copy of the patched package@version stays unpatched (yarn.lock has no inBundle, so the #325 fix can't see it) #758 follow-ups: a real registry package with
bundledDependencies.Maintainer request (global mode), what's left: the Windows MSI install of yarn, and a read-only prefix on Windows with a non-admin user. Global mode never finds yarn 1.0.x global packages:
yarn global dirdoesn't exist before yarn 1.1.0, and there's no fallback #437 (1.0.x) is still open. macOS case-insensitive name collisions.Packages whose upstream tarball root isn't
package/(old@types/*, e.g.@types/left-pad@1.2.0usesleft-pad/): the vendored prebuilt check requirespackage/…paths. Whether the real patch service normalizes the root can't be checked from the sandbox.Known non-bugs
Run-36 harness:
env.sh(mock env +Yfor$S/y<ver>),tr.sh <mode> <spec>(range-key battery),tm.sh(merged empty-range workspace),t692.sh, andmock_nosha1.py(the run-32 mock withsha1dropped from the grant, for Hosted yarn classic rewrite drops the#sha1fragment when the grant has no sha1, so yarn's cache serves stale bytes: yarn ≤1.17 silently installs the unpatched package, and yarn ≥1.19 fails every warm-cache install #558).patches-api.socket.devisn't used here. Use a local mock API (--api-url). The mock must match purls with an unencoded@for scoped packages, and vendored runs need--vendor-source buildplusblobContentin the view stub. For hostedvexon lock-only checkouts, pass--patch-server-url <mock>(CLI_CONTRACT "Patch hosts"); otherwisepackage_not_foundis expected.yarn 1.0.2 – 1.6.x install nothing (exit 0, empty node_modules) for
file:tarball lock entries and offline-mirror installs, even without socket-patch. Bisected in run 2: Node 10.24.1 / 14.21.3 / 16.20.2 / 22 all behave the same, and 1.7.0 works on all of them. The cause is in yarn, not Node or socket-patch, which is why CI reportsKNOWN LIMITATIONfor vendored ≤ 1.6. Not in docs/ecosystems.md.An
npm:alias entry is left unpatched in hosted mode withredirect_yarn_classic_alias_skipped(documented), andvexomits the package. (Exception: a vendored→hosted takeover that un-patches an alias copy the vendored wiring had patched is Vendored→hosted takeover on yarn classic un-patches a vendorednpm:alias copy when a direct copy is pinned, instead of retracting the takeover #1158.)Yarn classic hosted and vendored rewrites convert LF lines of a mixed CRLF/LF yarn.lock to CRLF, so rollback is not byte-exact #467 (vendored rewrite of a mixed CRLF/LF yarn.lock re-ends the block CRLF; rollback not byte-exact) was closed
not_plannedby a maintainer on 2026-10-08. The hosted half is fixed by Move all yarn.lock parsing into formats/yarn and stop pinning non-registry copies #1057. Don't re-file the vendored mixed-ending shape.A BOM plus no yarn header comment makes the first entry
entry_not_found. Yarn always writes the header, so this is synthetic.file:directory andlink:deps are skipped by design. (file:tarball deps are rewired and work.)The GitHub shorthand
owner/repo#taglocks as a codeload tarball and is correctly rewired; onlygit+…patterns are Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363.Running
scanfrom a workspace member dir whose deps are all hoisted: hosted says "No packages found" (exit 0, nothing to pin). Vendored refusesvendor_lockfile_missing(exit 1). Reclassified in run 21: when the member has its own non-hoisted copy, hosted's silent success is Hosted scan/get run from a yarn classic workspace member still reports success while pinning nothing: the #598 governing-root refusal covers pnpm and cargo only #884 (the Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 shape), not a documented posture.hosted→agent / vendored→agent keep the existing wiring (
hosted_wiring_retained/vendored_ownership_retained), as documented.Concurrent scans: the extras fail with
lock_held(intended).Probe branches can't be deleted from the sandbox (the git proxy rejects ref deletion). Leftovers:
bughunt/yarn-classic/20260930-mirror-git,bughunt/yarn-classic/20261001-win-crlf-git.v5 hosted
rollback/removeneed the npm registry. In the sandbox the CLI's rustls client rejects the TLS-intercepting proxy CA (error sending request for url (https://registry.npmjs.org/…)). That's a sandbox artifact. Use a local plain-HTTP registry passthrough withenv -u HTTPS_PROXY -u https_proxy SOCKET_NPM_REGISTRY=http://127.0.0.1:<port>. WithSOCKET_NPM_REGISTRYset, the restoredresolvedusesdist.tarballverbatim (registry.npmjs.org), not registry.yarnpkg.com. That's by design (npm.rsyarn_classic_tarball).v5 vendored mode has no local build (
--vendor-source buildis rejected). The mock must serve atarballartifact fromPOST …/patches/package.scan -galso reports npm's own bundled deps (npm global root), e.g.@isaacs/string-locale-compare. That's correct global discovery.Probe branch
bughunt/yarn-classic/20261001-global-modeis also left on the remote (the proxy blocks deletion).Hosted pins are recognized only on
patch.socket.devor the--patch-server-url/SOCKET_PATCH_SERVER_URLorigin. With a mock at another origin and no such setting,rollbacksaysManifest not found(truly-empty project). SetSOCKET_PATCH_SERVER_URL=<mock>.Hosted rollback of a lock without
integritylines (yarn < 1.10) addsintegritylines. That's the "default upstream entry", and yarn 1.7 still installs it frozen.Vendored mode on yarn ≤ 1.6 installs nothing. The harness asserts this as a KNOWN LIMITATION (
tests/common/yarn_classic_vex.rs:89); it's not in the user docs.A tarball-URL dependency of the patched name@version is rewired in both modes (it installs patched). Whether a URL "fork" should be refused, as vlt does, is a design question.
A SIGKILL can leave the lock wired with no
vendor/state.json.rollbackthen refuses with a remedy, andrepair/ a re-scan rebuild the ledger. That's intended crash handling.Hosted rollback ignores the
.yarnrcregistryand queriesSOCKET_NPM_REGISTRY(default registry.npmjs.org). That's documented (CLI_CONTRACT Hosted unwind / env table). SetSOCKET_NPM_REGISTRYbehind a private registry.A nested non-workspace project (its own
yarn.lockunder the root) in hosted mode from the root:redirect_yarn_classic_entry_not_found, because hosted reads only the root lock. That's the documented one-project model (run with--cwdper project).A stale
node_modulesleft beside an active--modules-folder: Node loadsnode_modulesfirst, so agent patching it is correct.Yarn classic never sends
.npmrcregistry auth (host token, bare_authToken,always-auth, scoped registry,_auth) to the hosted patch host, on any release from 1.0.2 to 1.22.22. The berry Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 leak doesn't apply to classic.Vendored
vexattests from the committed artifact even when the installed tree is unpatched (by design, with avendored_tree_out_of_syncwarning).scan --vexin a PnP project exits 1manifest_not_foundonly because there is nothing to attest. Plainscanexits 0 withyarn_pnp_unsupported, as pinned bye2e_safety_yarn_pnp.rs.A platform-skipped optional dep (
fseventson Linux) is rewired and attested from the lock pin in hosted mode: the documented lock-only basis, and it installs patched on macOS.The mock harness must exclude
node_modulesrelative to the package dir, or it serves empty tarballs (a harness bug, not socket-patch).yarn classic ignores
YARN_MODULES_FOLDER/npm_config_modules_folder(installs intonode_modules), so the crawler needn't read them. A~/.yarnrc--modules-folderresolves relative to$HOME, not the project.v5 has no
setupsubcommand. Agent cells useapply.Probe branch
bughunt/yarn-classic/20261002-dev-flowis also left on the remote (the proxy blocks deletion).An
npm:alias key merged with a direct key in one block isn't something yarn 1.22.22 writes (it emits two blocks), so don't test that shape.Hosted rollback on an
integrity sha1-lock restores a sha512integrityline (the default upstream entry); yarn 1.10 installs it frozen.patch.socket.dev/patches-api.socket.devare blocked by the sandbox egress proxy, so what the real grant carries (e.g. whethersha1is present) can't be checked from here.yarn 1.0.x–1.9.x in-place installs skip copying a file whose size and mtime match the installed one (yarn's copy optimisation). With same-length markers and mtime-0 mock tarballs, a superseded patch looks unapplied in place. Fresh installs and 1.10+ are fine. Use different-length markers in harnesses.
A
.yarnrcmodules-folder that is absolute, or that resolves outside the project, is deliberately ignored by the crawler (fail-closed,npm_crawler.rsresolve_modules_folder).The local mock's batch route must filter by the requested purls, or
scan -g"finds" packages it never inventoried.macOS probe harness: the first TCP connects to a freshly started Python mock on a macOS runner stall for 10–30 s. Before Bound patch API connects and stalled reads (#570) #581 the first
scan -gsimply took ~35 s. Since Bound patch API connects and stalled reads (#570) #581's 10 s connect bound, those batches fail (api_batch_failed/ "All N API batch queries failed", exit 1). This is a harness artifact: warm the mock with acurlloop before the first scan. Once warm,-greport / agent / vex pass on macOS.Agent mode patches a
link:/yarn linkdependency's target directory, even outside the project. That's the code Node loads; whether to refuse it is a design question.Leftover probe branches (deletion blocked):
bughunt/yarn-classic/20261003-global-rerun,bughunt/yarn-classic/20261003-macos-global.A symlinked
.socket/or.socket/vendor/npmin a single project works consistently in vendored mode (writes and cleans up at the link target). Only a store shared between projects is Vendored yarn classic writes and deletes through a symlinked .socket/vendor/npm dir, so rollback in one project deletes another project's vendored tarballs and breaks its frozen install #664.vex -ois--org, not--output. Use--outputin harnesses.Hosted rollback after
yarn removeof a patched package: pass (restores the remaining blocks, removes.socket/).Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261003-member-install.Quick vendored harness: a scratch cargo test using
tests/prebuilt_commonprepare_command(auto-mocks the service forvendor/repair) plus a staged.socket/manifest.json+ blob, as ine2e_vendor_yarn_classic_dev_flow.rs. Other commands (rollback / remove /vendor --revert/--check) run offline with the plain binary.A plain root
yarn add <pkg>@<new range>re-resolves a vendored block from the registry (unpatched). That's yarn's own behaviour; the follow-on rollback is Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665.A vendored lock after a hosted→vendored takeover, rolled back, restores
registry.npmjs.org(the hosted-unwound entry, viaSOCKET_NPM_REGISTRY), not the originalregistry.yarnpkg.com. Documented; frozen installs are fine.Agent-mode mock: serve
GET /v0/orgs/<org>/patches/blob/<hash>for both the before and the after hash.…/patches/diff/<uuid>may 404 (it falls back to blobs). Without the before blob, rollback reportsmissing_blob.vexin a workspace root whosepackage.jsonhas noversionexitsproduct_undetected. Pass--product.yarn classic itself merges
left-pad@1.3.0into an existingleft-pad@npm:async@1.3.0block (it installs the fork for the real name). That's a yarn bug; socket-patch fails closed on that block in all modes.With
yarn.lockandpackage-lock.jsonboth present, hosted rewrites both (and writes.npmrcallow-remote), and vendored wiresyarn.lockwithvendor_multiple_lockfiles. Intended.After
yarn removeof a vendored package,liststill shows the entry as "recorded in .socket/vendor/state.json". That's accurate about the ledger; the cleanup gap is Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665.Rebuilt the mock in run 15: the public-proxy path also calls
GET /patch/by-package/<purl>(aSearchResponsewith the patch summary) before/patch/view/<uuid>. Without it, scan says "could not fetch patch details".Windows probe harness: Git-Bash
seddrops CR bytes, so ased-normalised copy of yarn's CRLF lock never equals the original. Compare locks with rawcmp. Git-Bash also can't exec a program from a cwd longer than MAX_PATH; runyarn --cwd <long path>from a short dir.yarn 1.x on Windows writes new lockfiles with CRLF (
os.EOL,writeFilePreservingEol), and keeps an existing file's EOL. CRLF locks are therefore the default on Windows, not an edge case.Running
scan --mode agentfrom a workspace member dir finds nothing ("No packages found"), because the hoisted copies live under the root. That's the documented one-project model: run from the root.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261004-win-paths.Probe harness:
actions/upload-artifactdrops dot-directories (.socket/) unless you setinclude-hidden-files: true. A per-runner Python mock builds tarballs with that OS's zlib, so hashes differ across OSes. Ship one shared mock artifact for hosted cross-OS tests.get name@version(not a purl) runs the fuzzy package-name search, and against the mock it returnsno_packages. Use apkg:purl or a uuid.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261004-xos-vendored.Agent mode never crawls a workspace member under
vendor/,build/,dist/,tmp/,temp/,coverage/,__pycache__/or a hidden dir (e.g..github/actions/*), even when yarnworkspacesdeclares it. That's the documented walk (docs/ecosystems.md "npm: which node_modules trees are crawled"); whether declared workspaces should override it is a design question.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261005-agent-xos.Self-contained mock (run 18): one Python file serving
left-pad@1.3.0for all modes (batch, by-package, view withblobContent,…/packagegrant with a sha512+sha1 tarball artifact,/artifacts/<uuid>/…,blob/<hash>for before and after). It lives in the run-18 probe workflow onbughunt/yarn-classic/20261005-agent-xos.A
.gitattributes* text eol=crlf(forced text for every file) corrupts the vendored.tgzon checkout. The same setting corrupts every binary in the repo, so it's not filed;vendor --checkreports it (vendor_artifact_unreadable). vlt guards it with a<uuid>/.gitattributes* -text, and the tarball backend doesn't.* text=auto …and* text eol=lfare fine.Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363 / Vendored yarn classic writes and deletes through a symlinked .socket/vendor/npm dir, so rollback in one project deletes another project's vendored tarballs and breaks its frozen install #664 / After
yarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 were closed by Fix yarn classic rewiring git-sourced lock blocks (#363) #710 / Fix vendored revert deleting through a symlinked vendor dir (#664) #666 / Fix vendored revert keeping artifact for removed lock entry (#665) #689. Don't re-file the git-rewire shape; a git block is now skipped by design (docs/ecosystems.md "yarn classic git dependencies").yarn 1.0.2 installs a single copy (the git one, at the root) for a workspace that has both a registry block and a git block of the same
name@version. The hosted pin then never reachesnode_modules, but the scan'sredirect_yarn_classic_git_skippedwarning covers it andvexdoesn't attest.The sandbox can't reach codeload.github.com, so GitHub-shorthand deps need a probe branch.
Hosted rollback of a GitHub-shorthand dep (
owner/repo#tag, codeload lock) restores the npm registry tarball, not the codeload URL. CLI_CONTRACT "Hosted unwind coverage" says pins go back to the default upstream registry entry. Vendored rollback is byte-exact. Whether a non-registry origin should be refused (as composer does) is a design question.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261006-gh-shorthand.yarn 1.22.x refuses to install when
package.jsondeclares a berrypackageManager(corepack guard). To build a mid-migration fixture, install first and then add thepackageManagerfield.Building two PR worktrees into one
CARGO_TARGET_DIRcan reuse the first binary unchanged ("Finished in 0.18s"). Touch the sources or use separate target dirs, andcmpthe binaries.Agent-mode first-party refusal: JSON
apply.failedis 0 while the human summary says "1 failed" (status: partial_failure, exit 1). Cross-ecosystem and minor; not filed.Keep yarn's
--cache-folderoutside the project in harnesses, or agent mode also patches the cache copies under it.file:directory deps are first-party source for link-based managers, but yarn 1 copies them intonode_modules, and agent mode patches that copy. The hosted / vendored / VEX gap for that copy is Yarn classic VEX attests not_affected while afile:directory copy of the patched package@version installs unpatched, and hosted scan gives no warning for that copy #921, not a non-bug.A yarn project with no lockfile (
--install.no-lockfile) gets hostedsuccess/redirected: 0withredirect_npm_no_lockfile, whose text names only npm locks. The human stderr says nothing was switched, and vendored refuses with a message listing yarn.lock. Low-severity naming nit, not filed (pnpm has its ownredirect_pnpm_no_lockfile).--min-severityjudges severity fromvulnerabilities[].severityin/patch/by-package. A mock that returnsvulnerabilities: {}there makes every patch "unknown", so all of them are filtered. That's a harness artifact.--package pkg:npm/<name>@<version not installed>scans nothing and exits 0success. That's expected filtering.After a hosted scan,
yarn add/yarn upgrade/ member installs with a range that matches the pinned version merge into the pinned block (pin kept). Only an exact root re-add (yarn add -W <pkg> --exact) writes a separate registry block (Yarn classic VEX attests not_affected when yarn.lock also has a registry block for the patched name@version (e.g. afteryarn add -W <pkg> --exact), though yarn installs only the unpatched registry copy #938).Run-24 mock: a 3-package variant of the run-18 mock (left-pad high, ms low, scoped
@isaacs/string-locale-comparemedium, tarballs read from a local dir). Kill the mock in its own Bash call;pkill -f mock.pyin a command line that also containsmock.pykills the calling shell.link:deps: yarn 1 links every range of the same name to thelink:target (version "0.0.0"blocks), so alink:copy can't sit beside a registry block.Run-25 multi-package mock (
mockm.py <port> name@ver,…): downloads each upstream tarball, re-roots it topackage/, patchesindex.js/index.d.ts/package.json, one uuid per package. Vendored service artifacts must use apackage/root, or vendored refusesvendor_prebuilt_layout_mismatch.scan <PATH>in hosted / vendored mode is a per-directory--cwdrun (CLI_CONTRACT "Path-scoped scans"); with--jsonit takes one directory, so'packages/*'with two members is a usage error (exit 2) by design.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261007-musl-wrapper.rollback <PATH>/ agentscan <PATH>select at purl level: every copy of a selected package is handled, even copies outside the PATH (CLI_CONTRACT "Path-scoped scans"). Only the zero-selection miss is Agent-modescan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778.Hosted rollback in the sandbox needs
SOCKET_NPM_REGISTRY=http://127.0.0.1:<port>with a plain-HTTP passthrough to registry.npmjs.org (pythonurllibwith/root/.ccr/ca-bundle.crt) andHTTPS_PROXYunset. The restoredresolvedthen reads registry.npmjs.org + anintegrityline, so compare by a post-rollback frozen install, notcmp.The sandbox has a docker CLI but no daemon, and dl-cdn.alpinelinux.org / unofficial-builds.nodejs.org are blocked. Use a probe branch with
docker run node:22-alpinefor musl cells.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261007-musl-pr976.Probe harness:
cpfrom a read-only bind mount drops the exec bit on busybox, so overlay files withcat src > dstto keep the mode.v4.0.0 has no
scan --packageand novendor --check. Its vendored state (manifest + ledger) and hostedredirect-state.jsonare read correctly by main (run 27).Run-27 mock: the
mock.pymulti-package variant (mock.py <port> <left-pad tgz> [<is-number tgz>], one uuid per package, routes: batch / by-package / view / blob / package / artifacts). Use it withSOCKET_PROXY_URL+SOCKET_PATCH_SERVER_URL+SOCKET_API_URLpointed at the mock.Running
yarn config setas root writes/usr/local/share/.yarnrc(yarn's root user home), not$HOME/.yarnrc. In run 28 the sandbox was left withyarn-offline-mirror falsethere, which is the same as no mirror.yarn 4.18.1 run directly (not through corepack) ignores
packageManager: "yarn@1.22.22"and migrates a vendored v1 lock, dropping the vendored resolution. Theyarn_classic_berry_migration_riskwarning is suppressed by that pin, as documented (docs/ecosystems.md "yarn classic and yarn 2+"), and the code comment assumes berry refuses. Design note, not filed: through corepack the pin does select 1.22.22.yarn 1.22.22 writes
left-pad@1.3.0:and"x@npm:left-pad@1.3.0":as separate blocks; every earlier release checked (1.10.1 … 1.22.21) merges them. Alias-shape cells need 1.22.22.The REST search API (
/search/issues) is blocked from the sandbox. Use the GitHub MCPsearch_issuesfor duplicate checks; repo-scoped REST (/repos/…/issues,/pulls) works through the proxy.Run-29 harness:
scratchpad/battery.sh <bin> <out>(9 shapes × H/V, yarn 1.22.22, with 1.7.0 for the no-integrityshape) plusregpass.py(a plain-HTTP registry passthrough on :8790 for hosted rollback). The run-18 mock is still extracted from the20261005-agent-xosprobe branch; a no-sha1 variant is the same file with"sha1": SHA1dropped from the grant.yarn 1 deletes
.pnp.jswheninstallConfig.pnpis turned off and the project is reinstalled (1.22.22, run 30), so a stale yarn-1 loader needs a hand-committed file. Not a Yarn 4 node-modules / pnpm-linker projects migrated from Yarn 2 PnP keep a stale.pnp.js, and socket-patch refuses them as Plug'n'Play: agent and vendored exit 1, hosted warns "npm dependencies were NOT scanned" (regression since 3.3.0) #975 shape.yarn 1
workspacesignore!patterns (1.0.2–1.22.22):["packages/*", "!packages/b"]still installsbas a member. Any harness that tries to exclude a member with!gets the wrong layout.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261008-mirror-xos.Running
yarn config setas root writes/usr/local/share/.yarnrc; a probe harness must clean that too between cells, or mirror settings leak.yarn.lock + a stale pnpm-lock.yaml: vendored follows the governing-lock precedence (pnpm > yarn) and warns
vendor_multiple_lockfilesthat yarn.lock stays unpatched. Documented, not filed.A member-
.yarnrcmirror (Hosted yarn classic offline-mirror refusal misses a mirror set in a workspace member's .yarnrc, so installs run from that member fail the integrity check while the scan reports success and VEX attests #1115) only breaks installs once the mirror holds the upstream tarball (a cold member install populates it); a no-op member install after a root install leaves it empty.Agent mode overwrites a same-name@version
file:/ URL fork copy with Socket's patched file. That's the documented default mismatch policy (--strictrefuses), and the missing warning inscan --jsonis scan --mode agent --json and get --json overwrite a locally modified npm file without the documented content_mismatch_overwritten warning (not in the JSON, not on stderr) #1004. Hosted / vendored skip such copies (B16).A vendored fork-only yarn classic project exits 1 with
vendor_lock_entry_not_rewritable. Documented.An API purl that lowercases an uppercase npm name (
pkg:npm/jsonstream) fails closed in every mode. It can't be checked against the real service, so it's not filed. A case-preserving purl works.Leftover probe branch (deletion blocked):
bughunt/yarn-classic/20261008-grammar-xos.Run-32 harness:
battery.sh <yarnfn> <name> <deps> [resolutions](H/V,MUTATEhook),prune.sh,agent.sh, and a parameterised mock (MNAME/MVERenv). The probe script is in the run-32 workflow commit43a8c51.scan --vex <PATH>takes the output path; there's no--vex-output.get/scan--apply/--vendor/--no-applywere removed in Remove scan --apply/--vendor, get --no-apply and the download/gc aliases (#966) #1031: use--mode agent|vendored/--save-only.Member-dir cold-cache installs of a vendored yarn workspace fail whether or not there's a mirror (Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves the
file:./.socket/vendor/…tarball against the member dir #691). With a mirror, yarn falls back to the mirror's same-named upstream tarball, so the error readsIntegrity check failedinstead of "Tarball is not in network". Don't file it as a mirror bug.Run-34 harness:
hb.sh(hosted) /vb.sh(vendored, withPOST/MUThooks) /t1158.sh/tws.sh/tmir.sh, with the run-32mock.pyextracted from probe branch20261008-grammar-xos. yarn 1.22.22 lives at/opt/node-tools/node_modules/yarn/bin/yarn.jsin the sandbox.Run-35 harness:
h/env.sh(mock + plain-HTTP registryreg.pyon :8788 viaSOCKET_NPM_REGISTRY),probe.shfrom the20261008-grammar-xosworkflow,t828.sh/tlp2.sh/tws.sh. Give every project its own--cache-folder: yarn 1's global cache keys a localfile:tarball by name@version, so two projects with differentbund-1.0.0.tgzbytes get the wrong sha1 in the lock (a harness artifact, not a bug).Run-37 harness:
h/env.sh(MPORTpicks the mock;Bcan be overridden for PR builds),h/t.sh <ver> <mode> <name> <pkgjson>(PRE / FRESHCP / FCHK hooks; VEX runs in the fresh install and in a lock-only copy),mocksc.py(the run-32 mock with NAME set to@isaacs/string-locale-compare@1.1.0), andmocknosha.py(sha1 dropped from the grant).Hosted
vexrun in the tree that was installed before the scan refusesnot_applied. That's correct (node_modules still holds upstream bytes); run VEX after a fresh install or lock-only.repairis a no-op (exit 0) afteryarn upgrade/yarn adddrops a vendored pin. That matches docs/usage.md (repair restores artifacts and keeps the existing wiring).vendor --checkfails andvexrefusesvendor_unwired; re-run the vendored scan.yarn 1 (1.7.0 to 1.22.22) locks a workspace member's
file:./xdependency root-relative (name@file:./packages/a/x), so lock readers needn't resolve it relative to the member.All reactions