Skip to content

A report-only scan -g tells you to run socket-patch scan --mode agent [PATHS] without -g, so following the hint scans the cwd project instead of the global install #464

Description

[agent] Found by the scheduled npm bug-hunt routine (ledger #302).

Summary

In v5, scan -g without --mode is report-only. When it finds patches, it ends with this hint:

To apply these patches in place, run:
  socket-patch scan --mode agent [PATHS]
  socket-patch get <package-name-or-purl-or-CVE-ID>

The global flag isn't in either command. If you run the hint as printed, it scans the current project: it prints No packages found… and exits 0 outside a project, and inside one it patches the project's copies. The global install stays unpatched. --global-prefix <dir> and SOCKET_GLOBAL=1 show the same hint.

The Yarn Berry routine reported this first (handover on ledger #302); I confirmed it with npm.

Impact

Low severity (UX), but it was introduced in v5. In v4.0.0, scan -g applied the patches itself. Someone upgrading follows the new hint, gets exit 0, and their global tools stay vulnerable with no error.

Repro (Linux, npm 10.9.4, Node 22.22, mock patch API)

P=$(mktemp -d); W=$(mktemp -d)
npm i -g --prefix "$P" left-pad@1.3.0
cd "$W"
A="--api-url http://127.0.0.1:8765 --org o --api-token fake --patch-server-url http://127.0.0.1:8765"
NPM_CONFIG_PREFIX=$P socket-patch scan -g -e npm $A
#   ...
#   To apply these patches in place, run:
#     socket-patch scan --mode agent [PATHS]          <- no -g
#     socket-patch get <package-name-or-purl-or-CVE-ID> <- no -g
NPM_CONFIG_PREFIX=$P socket-patch scan --mode agent --yes $A    # the hint, verbatim
#   No packages found. Run your package manager's install first.   (exit 0)
head -c 20 "$P/lib/node_modules/left-pad/index.js"              # still the upstream bytes

I ran it twice in fresh directories with the same result. With -g added (scan -g --mode agent), the global copy gets patched.

Expected vs actual

  • Expected: the hint is a command that applies what the scan just reported. For a global scan that means socket-patch scan -g --mode agent and socket-patch get … -g, or --global-prefix <dir> when that's what was passed. The doc comment on report_only_hint says it's printed for "global with no mode", so it's meant for this case.
  • Actual: the commands have no scope flag, so they go to the project scope.

Matrix

OS npm Binary Result
Linux 10.9.4 main 2463257 ❌ hint has no -g (with -g and with --global-prefix)
Linux 10.9.4 v4.0.0 n/a: scan -g applies directly, no hint

The hint is a fixed string, so the behaviour is the same on every OS.

First bad version

Main 2463257 (#277, the v5 consolidation). v4.0.0 doesn't print the hint.

Suspect code

crates/socket-patch-cli/src/commands/scan/render.rs:252 report_only_hint() takes no arguments and returns fixed strings. It needs the global and --global-prefix context so it can add the matching flag.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions