Issue & discussion janitor log #576
Mikola Lysenko (mikolalysenko)
started this conversation in
General
Replies: 1 comment
|
[agent] Janitor: bridge test. The janitor/ledger workflow posted this comment on the routine's behalf. Hourly runs log here from now on. Generated by Claude Code |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Janitor: the hourly issue and discussion janitor rewrites this log each run. It shows the last run, the actions it took with a reason for each, a rolling list of recent actions, deferred candidates, and anything that needs a human. The routine writes it to the
janitor/ledgerbranch, and a workflow on that branch applies it here.Last run
2026-10-04 13:21 UTC on origin/main
045d7ec7. 276 open issues and 55 open PRs were reviewed.This run
045d7ec7and no PR has merged since Bound patch API connects and stalled reads (#570) #581 (2026-10-02 19:59Z), so no issue has a new fix to verify. The 12 open issues that merged PRs mention (Maven CI matrix has no Windows leg, a stale 4.0 RC, and no legs at the resolver boundaries #267, npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325, Agent mode ignores pnpm's virtualStoreDir: transitive dependencies are reported package_not_installed with a custom virtualStoreDir or the global virtual store #362, scan/get --json drop the agent-mode apply failure: exit 1 with failed: 0, the patch shown as "added", and no error anywhere (e.g. a read-only global ~/.m2) #424, Global mode never finds yarn 1.0.x global packages:yarn global dirdoesn't exist before yarn 1.1.0, and there's no fallback #437, Composer crawler ignores a vendor-dir set in the global Composer config, so scan -g and agent scans report "No packages found" and leave installs unpatched #439, Vendored pnpm 12 withpackageManagerset: the two-document pnpm-lock.yaml makes vendor refuse, andvendor --revert, rollback and the hosted takeover half-revert the project and break frozen installs #466, Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473, Since #446,scan -g --mode agentthenrollback -gfrom a vendored NuGet project reverts the project's patched package in the shared global packages folder; the locked restore stays "up-to-date" and VEX keeps attesting #489, Agent-mode scan in a Pipenv project without a Pipenv venv patches the system Python's site-packages in place instead of the project's venv/ (regression from #388) #504, Hosted NuGet mapping reads commented-out package sources #561, Patch blob and diff downloads buffer the whole response body with no size cap #571) are all cited as "related" or "not fixed here", never as closed by the PR. The ~70 new issues (Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697–Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783) are not duplicates. Spot checks on origin/main match their claims: Read the go.mod module directive through go_mod_edit and delete the crawler's unused parse_go_mod_module #781 (parse_go_mod_moduleis called only from tests),scan --mode hosted --dry-run --vex <path> --jsondrops the documentedvex: {skipped: true, reason: "dry_run"}marker (agent and vendored scans emit it) #744 (onlyembed_vex_into_jsonand the vendor arm emit thedry_runmarker), and Maven pom edits insert LF lines into CRLF pom.xml files (hosted and vendored) #273 (insert_maven_repositoryandrepository_blockstill emit bare\n). Close calls: uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742/Vendored requirements.txt never picks up a superseding patch: the re-vendor to a new uuid fails with pypi_requirements_already_vendored (exit 1), though--dry-runpreviewswould_revendorand the contract says it re-vendors automatically #765/Vendored Pipenv never picks up a superseding patch: re-vendor to a new uuid fails with pypi_pipenv_source_already_exists (lock-only) or a false package_not_installed (venv present), exit 1 #769/Bun lockfile-only checkouts can't see hosted pins: hosted re-runs never pick up a superseding patch andscan --mode vendoredskips the takeover, both reporting success with 0 packages #720/Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650 (superseding patch never picked up) are the same symptom in different PMs with different code paths. Route purl ecosystem checks through Ecosystem::from_purl instead of 24 inline starts_with("pkg:<type>/") tests #747 is a sub-item of tracking issue Tracking: build and classify purls through one validated utils::purl API #748, and Vendored Maven refuses a single-module EAR pom as a multi-module aggregator because two declares_modules disagree #716/Locate hosted Maven pom edits and their upstream restore through the formats::maven element scanner #717 are sub-items of Tracking: read and edit pom.xml through one element scanner in formats::maven #715. Vendored gem refuses a gem whose spec is not in the lock's first GEM section #779 is a bug and Read Gemfile.lock sections and DEPENDENCIES entries through formats::gem in hosted and vendored modes #780 is the refactor that would fix it. Hosted scan on a Rush repo with pnpm 11/12 reports success, butrush installthen fails with ERR_PNPM_TARBALL_URL_MISMATCH, or (pnpm 11.0.0) silently installs the upstream package #713 and Hosted scan on a Rush repo with subspaces never emitsredirect_rush_repo_state_stale, sorush installfails on the shrinkwrap hash check with no warning #714 (Rush) have different triggers.pm:*label, and no closed issue carriesagent:claimed. Agent-modescan packages/<member>finds nothing in a pnpm workspace (exit 0), whilerollback packages/<member>selects the same packages #778–Vendored yarn berry misses a parent-scoped userresolutionsentry (pkg-a/left-pad), reports success, and everyyarn install --immutablefails YN0028 #783 are still waiting for triage, which the janitor leaves to the triage agent.2026-10-02T13:56:32Z-gradle21) maps to open PR Full Gradle support in agent, hosted and vendored modes #646.scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434) still carry drift that was already reported. Bug hunt ledger: PDM #312 still lists closed Agent mode writes the patch into PDM's shared install cache when PDM 2.0–2.12 installs packages as directory symlinks (install.cache + symlink) #332, Global scan (-g) never crawls PDM's global project venv or PDM-managed interpreters, sopdm add -gpackages are silently left out with exit 0 #451 and Agent and hosted mode ignore the interpreter PDM records in .pdm-python (venv.in_project = false, pdm use <venv>), so the real env is skipped or a stray .venv / the PATH python is patched, and VEX attests an unpatched install #502 asfail, already reported on 2026-10-02. Benchmark progress: socket-patch scan #575 has been corrected (it now marks Perf regression: vlt/hosted wall +127% (1169ae68, #472) #579 closed). No ledger cites an issue number that doesn't exist, and no PM has two ledgers.Recent actions (rolling, newest first)
scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 for Windows)scan -gofficial-installer row isfailbut points only at closed Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS #415; no open issue tracks it)fail)agent:claimedfrom closed The patch API client has no request timeout, so scan, get and apply hang forever on a stalled server #570 (closed as completed by PR Bound patch API connects and stalled reads (#570) #581)agent:claimed(no PR for the remaining half, claimer silent for more than 48h)agent:claimedfrom closed Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (closed as completed, so the claim is finished)agent:claimedfrom closed Pipenv recognizes hosted PyPI patch URLs with two private grammars that disagree with the shared one #563 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect rewrites only the first of a gem's declarations, so a gem listed in twogroupblocks makes everybundle installfail with "You cannot specify the same gem twice" #548 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)agent:claimedfrom closed Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 (closed as completed, so the claim is finished)agent:claimedfrom closed Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 (closed as completed, so the claim is finished)agent:claimedfrom closed npm apply exits 1 when every patch targets a platform-skipped optional dependency (fsevents, @esbuild/*), so the setup hook fails npm ci and npm install on other OSes #403 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 (closed as completed, so the claim is finished)agent:claimedfrom closed With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 (closed as completed, so the claim is finished)agent:claimedfrom closed Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468 (closed as completed, so the claim is finished)agent:claimedfrom closed Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 (closed as completed, so the claim is finished)agent:claimedfrom closed Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed as completed, so the claim is finished)fail)fail)fail)fail)agent:claimedfrom closed On Windows (RubyInstaller),scan -g/get -g/vex -gfind no global gems becausegem envis spawned as baregem, which never resolves togem.cmd#421 (closed as completed, so the claim is finished)agent:claimedfrom closed On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 (closed as completed, so the claim is finished)agent:claimedfrom closed On Windows, scan -g finds no Composer global packages in the default %APPDATA%\Composer home, so apply -g and vex -g silently do nothing #438 (closed as completed, so the claim is finished)agent:claimedfrom closedscan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)Deferred / unsure
cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533, Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551) → Full Gradle support in agent, hosted and vendored modes #646; Vendored pnpm with two or more packages: vendor --revert and rollback leave an emptypnpm.overridesin package.json and (lockfile 9.0) a scaffolded pnpm-workspace.yaml behind #636 and Vendored uv with two or more packages: vendor --revert (and remove in purl order) leave an empty[tool.uv.sources]header in pyproject.toml #670 → Fix vendored revert leaving created scaffold behind (#636, #670) #672; Vendored yarn classic writes and deletes through a symlinked .socket/vendor/npm dir, so rollback in one project deletes another project's vendored tarballs and breaks its frozen install #664 → Fix vendored revert deleting through a symlinked vendor dir (#664) #666; npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325 → Fix in-run hosted VEX attesting npm bundled copies (#325) #669; npm lockfileVersion 1: scan/get --mode vendored un-host a hosted patch and then refuse to vendor it, so the project silently goes back to unpatched (vendor eject rolls back correctly) #659 → Fix npm v1 lock losing a hosted patch on takeover (#659) #660 and Fix gem takeover un-hosting a grouped gem (#775) #776; Gem hosted → vendored takeover un-hosts a gem declared inside agroupblock and then refuses to vendor it (gemfile_declaration_not_editable), so the project silently goes back to unpatched #775 → Fix gem takeover un-hosting a grouped gem (#775) #776; Poetry venv discovery expands a{project-dir}placeholder Poetry doesn't have, so agent mode misses the env, patches the global interpreter, and VEX attests not_affected #608 and Global scan (-g) never crawls the venv that Poetry's official installer creates ($POETRY_HOME/venv), so patches for Poetry's own dependencies are never found, applied or rolled back #640 → Fix Poetry data-dir and placeholder model (#608, #640) #644; Agent mode skips ./.venv when PIPENV_VENV_IN_PROJECT=0 or PIPENV_NO_VENV_IN_PROJECT=1 is set, but Pipenv 2018 through 2023.10.24 still use that .venv, so it stays unpatched and VEX attests not_affected (regression from #388) #645 and Pipenv venv discovery ignores the project's .env, so a PIPENV_CUSTOM_VENV_NAME or WORKON_HOME set there leaves the Pipenv venv unpatched, patches the system Python instead, and VEX attests not_affected #546 → Fix Pipenv venv discovery settings view (#645, #546) #654; Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628 and Share the yarn berry project gates between hosted and vendored modes #629 → Fix yarn berry project gates drifting between modes (#628, #629) #657; Agent-mode apply writes through node_modules links into first-party source (npm workspace members, file: deps, npm link targets), overwriting the user's code, and rollback restores upstream bytes instead #626 → Fix agent mode patching linked first-party source (#626) #634; Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 and Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473 → Fix uv hosted unwind declaration matching (#606, #473) #625; Hosted gem redirect breaks a multi-linegemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340 → Fix hosted gem redirect breaking multi-line and conditional gem lines (#340) #637; vlt lock inventory and hosted restore resolve a node's registry differently #562 → Resolve vlt registry bases through one shared function (#562) #574; Patch blob and diff downloads buffer the whole response body with no size cap #571 → Stream patch blob and diff downloads to disk (#571) #607; Gem settings resolution skips Bundler's global config (~/.bundle/config/BUNDLE_USER_CONFIG), so a globalcache_pathorgemfilegets no warning or refusal and VEX attests an unpatched install #577 → Fix Bundler global config being ignored (#577) #621; npm vendored vex and vendor --check pass while a second registry copy of the patched package@version in the same package-lock.json stays unwired and installs unpatched #588 → Fix npm/Bun VEX attesting a patch a same-lock copy skips (#588) #589; Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 and Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417 → Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) #598; NuGet and Cargo crawlers hang on a FIFO at obj/project.assets.json or vendor/<crate>/Cargo.toml #592 → Read NuGet and Cargo crawler project files through the FIFO-safe reader (#592) #602; Agent-mode apply skips a bundled copy inside another vlt/pnpm store entry whenever the package is also installed normally, and VEX attests not_affected #601 and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 → Fix npm store copies missed by agent apply and vex (#601, #603) #605; PDM PEP 582 detection missespython.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 and Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 → Fix PDM settings ignoring PDM's config layers (#609, #566) #611; Vendored Hatch runs ahatchexecutable planted in the scanned project #613 → Fix vendored Hatch running a planted hatch (#613) #617; Hatch hosted→vendored takeover with two or more patches leaves allow-direct-references = true (plus empty [tool]/[tool.hatch] tables) behind after rollback or remove, disabling Hatchling's direct-reference guard #674 → Fix Hatch takeover leaving direct-ref permission (#674) #680; Hosted gem redirect ignores Bundler'smirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681 → Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684; Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 → Fix vendored revert keeping artifact for removed lock entry (#665) #689; Agent mode ignores pnpm'smodulesDir: on pnpm 10.12+ every installed package is "not installed", and apply exits 0 leaving it unpatched #661 and Hosted pnpm vex attests not_affected over an unpatched install when pnpm'smodulesDiris set (pnpm 10.12+), because the missed install is treated as "nothing installed" #696 → Fix pnpm modulesDir store being skipped (#661, #696) #698; Share the poetry.lock and pdm.lock fragment-splice engine instead of keeping two copies #694 and Poetry and PDM lock rewrites flip a mixed-line-ending lock's edited unit in opposite directions #695 → Fix Poetry/PDM lock splice drift (#694, #695) #703; Vendored → hosted takeover strands a requirements.txt pin that lives in a-rinclude or a vendored "(transitive)" line: the wet run reverts it to the unpatched release, while--dry-runpreviews a clean takeover #699 → Fix PyPI vendored→hosted takeover stranding unreachable pins (#699) #708; Yarn berry vendored and hosted pins putchecksum:out of yarn's field order on platform-conditional lock entries (conditions: os=…), so everyyarn install --immutablefails YN0028 #697 and Yarn berry vendored and hosted pins copy the registry entry'sbin:paths, but yarn re-reads them from the tarball (./dist/bin/uuid), so vendored installs and hardened hosted installs fail YN0028 for packages like uuid and acorn #718 → Fix yarn berry pin entry rendering (#697, #718) #719; Hosted gem VEX attestsnot_affectedfor an unpatched install when.bundle/configsets an out-of-treepath(absolute or~/…), because the skipped bundle root counts as "nothing installed" #709 → Fix gem VEX ignoring out-of-tree bundle path (#709) #712; Hosted and vendored yarn classic modes rewire git-sourced yarn.lock entries, so every later yarn install fails while scan and VEX report success #363 → Fix yarn classic rewiring git-sourced lock blocks (#363) #710; Hosted and lock-only scans treat a UTF-16 requirements.txt (what Windows PowerShell'spip freeze >writes) as absent: exit 0, no warning, and pip keeps installing the unpatched pin #721 → Fix UTF-16 requirements.txt silently skipped (#721) #724;vendor --checksays "committed artifact and wiring verified" (exit 0) afterpipenv lockdrops the vendored reference, so a freshpipenv install --deployinstalls the unpatched wheel while vex says vendor_unwired #725 → Fix vendor --check passing unwired vendored entries (#725) #730; Hosted Hatch rewrite leaves an existing Hatch environment unpatched with no stale-install warning, and vex still attests not_affected #335 → Fix Hatch environments being invisible to stale-install checks and VEX (#335) #700; Hosted gem redirect treats agitlab:or customgit_sourcegem as patched, so Bundler keeps loading the unpatched git checkout while VEX attestsnot_affected#652 → Fix gem source-option guard missing git sources (#652) #731; Bun lockfile-only checkouts can't see hosted pins: hosted re-runs never pick up a superseding patch andscan --mode vendoredskips the takeover, both reporting success with 0 packages #720 → Fix Bun lockfile inventory skipping hosted pins (#720) #722; Human-output scan --mode agent / --sync still never re-applies an already-recorded patch after a reinstall (#454 fixed only the --json path) #732 → Fix human scan skipping re-apply of recorded patches (#732) #733; npm agent-mode apply never patches an npm-aliased install (lp@npm:left-pad), yet VEX attests the package not_affected #356 → Fix agent mode skipping npm-aliased copies (#356) #738; Hosted and vendored modes refuse every valid bun.lockb that holds a release and a prerelease of the same version (X@1.0.0 + X@1.0.0-beta.1) as "metadata hash does not match"; hosted exits 0 with nothing patched (regression since 4.0.0) #739 → Fix bun.lockb prerelease order in hash check (#739) #741; Hatch never picks up a superseding patch: re-scan refuses its own earlier wiring ("existing direct source must be reverted"), so hosted exits 0 still pinned to the old patch uuid #650, uv projects never pick up a superseding patch: hosted re-scan lists the upgrade in updates[] but refuses its own earlier [tool.uv.sources] pin (exit 0, still on the old uuid), and vendored re-scan fails pypi_uv_source_already_exists #742 and Vendored requirements.txt never picks up a superseding patch: the re-vendor to a new uuid fails with pypi_requirements_already_vendored (exit 1), though--dry-runpreviewswould_revendorand the contract says it re-vendors automatically #765 → Fix uv/Hatch hosted re-pin to a newer patch (#742, #650) #743 and Fix vendored requirements.txt re-vendor to a superseding patch (#765) #766; A failed vendor eject rewrites every file in the project root from its snapshot, sovendor --json > report.json(or> vendor.log 2>&1) in the project loses the output and concurrent writes to root files are reverted #687 → Fix failed eject rewriting every root file (#687) #752; Vendored pnpm 7/8 writes the absolutefile:specifier unquoted, so a project path containing#or:breaks every frozen install while vendor,vendor --checkand vex report success #754 → Fix pnpm 7/8 vendored specifier YAML quoting (#754) #755; Hosted yarn berry pin of acatalog:dependency keysresolutionsby the resolvednpm:range, so everyyarn install --immutablefails YN0028 (regression from #465) #632 → Fix yarn berry hosted pin of catalog deps (#632) #763; Lock inventory reads only Gemfile.lock, so a gems.rb project's gems.locked is invisible and a stale Gemfile.lock is read instead #736, Hosted gem redirect ignores Bundler 4's custom lockfile (lockfilesetting /BUNDLE_LOCKFILE), so it never pins the lock Bundler uses and frozen installs fail with no warning #749 and Hosted gem redirect wiresgems.rbin a Gemfile/gems.rb twin locked by Bundler 1.17, which loadsGemfile, so the install stays unpatched while the in-run VEX attests it #751 → Fix gem pair model ignoring custom lockfile and Bundler 1 twins (#749, #751) #768; Agent-mode apply reportsalready_patched/applied: 0when it actually patched an unpatched pnpm peer-variant copy (the store-copy pass's writes are never reported) #756 and Share one pnpm/vlt store-copy fan-out between agent apply and rollback, folding each copy's per-file records #772 → Fix store-copy fold dropping copy writes (#756, #772) #774; A report-onlyscan -gtells you to runsocket-patch scan --mode agent [PATHS]without-g, so following the hint scans the cwd project instead of the global install #464 → Fix report-only scan -g hint dropping -g (#464) #777.3efdc31d) still looks valid on origin/main, so it stays open.Needs a human
agent:needs-humanissues waiting on a decision: Benchmark tracking: socket-patch scan #580, Decide: give SOCKET_FORCE per-command names so forcing a self-update doesn't also force apply and vendor #615, Decide: where patch API calls go when a token is set but the org slug can't be resolved #648, Decide: one shape for the--jsontop-levelerror(scan and get emit both a string and a {code, message} object) #704.vexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed by Fix agent vex checking only one installed copy (#516) #517 while Deno_1copies are still missed) now has a Deno follow-up: Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603. A human can drop this item unless they want Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 reopened instead.janitor/ledgerbranch requires signed commits. Pushes signed with the default session identity work, but pushes made under a customuser.name/user.emailare rejected (GH013).Generated by Claude Code
All reactions