Every merge-queue entry now fails ci-ok: production stopped publishing the free minimist@1.2.2 patch
Between 15:29Z and 15:49Z on 2026-10-09, patches-api.socket.dev stopped returning any free patch for pkg:npm/minimist@1.2.2. Before that, the pinned patch was 80630680-4da6-45f9-bba8-b888e0ffd58c (CVE-2021-44906). Several CI suites are hard-pinned to that package. Two of those jobs feed ci-ok, so every merge_group run fails.
Evidence
hosted-e2e passed in all 5 merge_group runs that finished between 15:28 and 15:29Z, for example 37951440882.
hosted-e2e failed on all 3 attempts in PR run 37954180942 (job 113901363597) and in merge_group run 37954543526 (pr-1284). 9 of 16 tests failed:
preflight_required_patches_are_published:
pkg:npm/minimist@1.2.2: production publishes NO free patches for this package anymore.
The npm, shrinkwrap, pnpm, yarn classic, yarn berry, bun and vlt install proofs all report packagesWithPatches: 0. The pypi and gem legs still pass, so the API itself is up.
e2e (ubuntu-latest, e2e_safety_pnpm) failed in both runs: apply through the public proxy no longer patches minimist/index.js. That gives a hash mismatch, plus a missing layout note.
- The UUID
80630680-… appears in 37 files, so other suites that hit the live proxy will fail too: e2e_npm, e2e_bun_lockb, e2e_vendored_production, scripts/backtest-bun.py, scripts/backtest-vlt.py, vlt-serve-watchdog.yml and the Bun compatibility workflow.
Options
- Immediate unblock for
hosted-e2e: set repo variable HOSTED_E2E_DISABLED=true (the escape hatch documented in ci.yml), then re-run failed jobs. This does not fix e2e_safety_pnpm, which has no kill switch.
- If the withdrawal was unintended (a catalog or proxy regression), republish or restore the free minimist@1.2.2 patch. That fixes everything with no code change. Please check with the patches-api owners first.
- If it was intentional, repin the suites to another published free npm patch, following
docs/testing/hosted-production-e2e.md § "If a required patch is withdrawn". That means updating the UUID, PURL, pristine/patched hashes and marker across the tests and scripts above. Doing it needs live read access to patches-api.socket.dev, which the janitor sandbox does not have.
Found by the hourly CI janitor.
Generated by Claude Code
Every merge-queue entry now fails
ci-ok: production stopped publishing the free minimist@1.2.2 patchBetween 15:29Z and 15:49Z on 2026-10-09,
patches-api.socket.devstopped returning any free patch forpkg:npm/minimist@1.2.2. Before that, the pinned patch was80630680-4da6-45f9-bba8-b888e0ffd58c(CVE-2021-44906). Several CI suites are hard-pinned to that package. Two of those jobs feedci-ok, so every merge_group run fails.Evidence
hosted-e2epassed in all 5 merge_group runs that finished between 15:28 and 15:29Z, for example 37951440882.hosted-e2efailed on all 3 attempts in PR run 37954180942 (job 113901363597) and in merge_group run 37954543526 (pr-1284). 9 of 16 tests failed:packagesWithPatches: 0. The pypi and gem legs still pass, so the API itself is up.e2e (ubuntu-latest, e2e_safety_pnpm)failed in both runs:applythrough the public proxy no longer patchesminimist/index.js. That gives a hash mismatch, plus a missing layout note.80630680-…appears in 37 files, so other suites that hit the live proxy will fail too:e2e_npm,e2e_bun_lockb,e2e_vendored_production,scripts/backtest-bun.py,scripts/backtest-vlt.py,vlt-serve-watchdog.ymland the Bun compatibility workflow.Options
hosted-e2e: set repo variableHOSTED_E2E_DISABLED=true(the escape hatch documented inci.yml), then re-run failed jobs. This does not fixe2e_safety_pnpm, which has no kill switch.docs/testing/hosted-production-e2e.md§ "If a required patch is withdrawn". That means updating the UUID, PURL, pristine/patched hashes and marker across the tests and scripts above. Doing it needs live read access topatches-api.socket.dev, which the janitor sandbox does not have.Found by the hourly CI janitor.
Generated by Claude Code