Issue & discussion janitor log #576
Mikola Lysenko (mikolalysenko)
started this conversation in
General
Replies: 1 comment
|
[agent] Janitor: bridge test. The janitor/ledger workflow posted this comment on the routine's behalf. Hourly runs log here from now on. Generated by Claude Code |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Janitor: the hourly issue and discussion janitor rewrites this log each run. It shows the last run, the actions it took with a reason for each, a rolling list of recent actions, deferred candidates, and anything that needs a human. The routine writes it to the
janitor/ledgerbranch, and a workflow on that branch applies it here.Last run
2026-10-03 13:20 UTC on origin/main
045d7ec7. 214 open issues and 31 open PRs were reviewed.This run
045d7ec7) and no PR has merged since Bound patch API connects and stalled reads (#570) #581. New issues Vendored NuGet doesn't recognise a close tag with whitespace (</packageSources >,</packageSourceMapping >), so it appends a second section that NuGet ignores and every restore fails NU1100 / NU1403 while scan reports success and VEX attests #685–npm vendored refuses a registry package with vendor_workspace_member whenever a local file: directory (or workspace member) has the same name@version, and the hosted→vendored takeover then un-hosts it, leaving it unpatched #688, Vendored yarn classic wiring breaks every install run from a workspace member directory: yarn resolves thefile:./.socket/vendor/…tarball against the member dir #691–Hosted pnpm vex attests not_affected over an unpatched install when pnpm'smodulesDiris set (pnpm 10.12+), because the missed install is treated as "nothing installed" #696 are not duplicates: Hosted pnpm vex attests not_affected over an unpatched install when pnpm'smodulesDiris set (pnpm 10.12+), because the missed install is treated as "nothing installed" #696 (hosted pnpm vex withmodulesDir) differs from Agent mode ignores pnpm'smodulesDir: on pnpm 10.12+ every installed package is "not installed", and apply exits 0 leaving it unpatched #661 (agent-mode apply); Hosted Composer vex attests not_affected for an unpatched package when config.vendor-dir is absolute or uses ~/ or $HOME/ #686 (absolute/~Composer vendor-dir in hosted vex) differs from Composer crawler ignores a vendor-dir set in the global Composer config, so scan -g and agent scans report "No packages found" and leave installs unpatched #439 (global-config vendor-dir); Vendored yarn classic rollback can't undo a block yarn has merged with another range (left-pad@^1.1.0, left-pad@^1.3.0:): it reports the block as gone, exits 1 forever and leaves the lock wired #692 (yarn-merged range block) is a sibling of Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 (removed lock entry), noted on Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 itself, with a different trigger.pm:*label, and no closed issue carriesagent:claimed.mirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681 → PR Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684 and Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 → PR Fix vendored revert keeping artifact for removed lock entry (#665) #689 are open; every other claim still has an open PR.vlt/*regression).Recent actions (rolling, newest first)
scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 for Windows)scan -gofficial-installer row isfailbut points only at closed Global scan (-g) never crawls pipx venvs, so the dependencies of a pipx-installed Hatch are never reported, patched or rolled back on any OS #415; no open issue tracks it)fail)agent:claimedfrom closed The patch API client has no request timeout, so scan, get and apply hang forever on a stalled server #570 (closed as completed by PR Bound patch API connects and stalled reads (#570) #581)agent:claimed(no PR for the remaining half, claimer silent for more than 48h)agent:claimedfrom closed Poetry hosted ⇄ vendored mode switch is refused, and blames a "user-authored" source that socket-patch wrote itself #328 (closed as completed, so the claim is finished)agent:claimedfrom closed Pipenv recognizes hosted PyPI patch URLs with two private grammars that disagree with the shared one #563 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect appends a second declaration when the gem is declared througheval_gemfileor a loop, so everybundle installfails with "You cannot specify the same gem twice" #482 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted gem redirect rewrites only the first of a gem's declarations, so a gem listed in twogroupblocks makes everybundle installfail with "You cannot specify the same gem twice" #548 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)agent:claimedfrom closed Bun isolated linker: transitive packages under node_modules/.bun are "not installed" in agent mode, and scan --mode agent exits 0 with them unpatched #366 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted → vendored takeover on yarn berry reverts the hosted redirect before a per-package vendor refusal, leaving the package unpatched in both modes #369 (closed as completed, so the claim is finished)agent:claimedfrom closed Deno nodeModulesDir: transitive npm packages under node_modules/.deno are "not installed", and apply/scan exit 0 leaving them unpatched #373 (closed as completed, so the claim is finished)agent:claimedfrom closed npm apply exits 1 when every patch targets a platform-skipped optional dependency (fsevents, @esbuild/*), so the setup hook fails npm ci and npm install on other OSes #403 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted yarn berry redirect makes yarn send the project's npm registry auth token to the patch host #404 (closed as completed, so the claim is finished)agent:claimedfrom closed With Bun's isolated linker,vexattests a hosted patch as not_affected (verified) while the installed copy under node_modules/.bun is still unpatched (v5 regression) #405 (closed as completed, so the claim is finished)agent:claimedfrom closed Vendored → hosted takeover on yarn berry deletes the vendored patch, then skips the hosted rewrite when the grant has no yarnBerry10c0 checksum, and still exits 0 "fully hosted" #468 (closed as completed, so the claim is finished)agent:claimedfrom closed Yarn 4 pnpm linker: transitive packages that live only in node_modules/.store are "not installed" in agent mode and stay unpatched #495 (closed as completed, so the claim is finished)agent:claimedfrom closed Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed as completed, so the claim is finished)fail)fail)fail)fail)agent:claimedfrom closed On Windows (RubyInstaller),scan -g/get -g/vex -gfind no global gems becausegem envis spawned as baregem, which never resolves togem.cmd#421 (closed as completed, so the claim is finished)agent:claimedfrom closed On Windows,scan -g/get -g/vex -gfind no global npm packages becausenpm root -gis spawned as barenpm, which never resolves tonpm.cmd#434 (closed as completed, so the claim is finished)agent:claimedfrom closed On Windows, scan -g finds no Composer global packages in the default %APPDATA%\Composer home, so apply -g and vex -g silently do nothing #438 (closed as completed, so the claim is finished)agent:claimedfrom closedscan -ginside a Yarn Berry project runs the project'sglobalpackage.json script and scans whatever directory it prints as a global install #440 (closed as completed, so the claim is finished)agent:claimedfrom closed Hosted requirements.txt rewrite skips PEP 440-equivalent pins likesix==1.16for an installed 1.16.0, soscanexits 0 and pip installs the unpatched release (regression from v4.0.0) #475 (closed as completed, so the claim is finished)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)fail)Deferred / unsure
cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533, Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551) → Full Gradle support in agent, hosted and vendored modes #646, Vendored pnpm with two or more packages: vendor --revert and rollback leave an emptypnpm.overridesin package.json and (lockfile 9.0) a scaffolded pnpm-workspace.yaml behind #636 and Vendored uv with two or more packages: vendor --revert (and remove in purl order) leave an empty[tool.uv.sources]header in pyproject.toml #670 → Fix vendored revert leaving created scaffold behind (#636, #670) #672, Vendored yarn classic writes and deletes through a symlinked .socket/vendor/npm dir, so rollback in one project deletes another project's vendored tarballs and breaks its frozen install #664 → Fix vendored revert deleting through a symlinked vendor dir (#664) #666, npm VEX attests not_affected while a bundled (inBundle) copy of the same package@version stays unpatched #325 → Fix in-run hosted VEX attesting npm bundled copies (#325) #669, npm lockfileVersion 1: scan/get --mode vendored un-host a hosted patch and then refuse to vendor it, so the project silently goes back to unpatched (vendor eject rolls back correctly) #659 → Fix npm v1 lock losing a hosted patch on takeover (#659) #660, Poetry venv discovery expands a{project-dir}placeholder Poetry doesn't have, so agent mode misses the env, patches the global interpreter, and VEX attests not_affected #608 and Global scan (-g) never crawls the venv that Poetry's official installer creates ($POETRY_HOME/venv), so patches for Poetry's own dependencies are never found, applied or rolled back #640 → Fix Poetry data-dir and placeholder model (#608, #640) #644, Agent mode skips ./.venv when PIPENV_VENV_IN_PROJECT=0 or PIPENV_NO_VENV_IN_PROJECT=1 is set, but Pipenv 2018 through 2023.10.24 still use that .venv, so it stays unpatched and VEX attests not_affected (regression from #388) #645 and Pipenv venv discovery ignores the project's .env, so a PIPENV_CUSTOM_VENV_NAME or WORKON_HOME set there leaves the Pipenv venv unpatched, patches the system Python instead, and VEX attests not_affected #546 → Fix Pipenv venv discovery settings view (#645, #546) #654, Hosted yarn berry rewrites a mixed-line-ending package.json that vendored mode refuses #628 and Share the yarn berry project gates between hosted and vendored modes #629 → Fix yarn berry project gates drifting between modes (#628, #629) #657, Agent-mode apply writes through node_modules links into first-party source (npm workspace members, file: deps, npm link targets), overwriting the user's code, and rollback restores upstream bytes instead #626 → Fix agent mode patching linked first-party source (#626) #634, Hosted uv rollback, remove and vendored takeover refuse when the patched package is declared with different specifiers independenciesand an extra (or under different markers), although each lock entry keeps its marker #606 and Hosted uv rollback and remove refuse when the patched package reaches a dependency group through PEP 735include-group#473 → Fix uv hosted unwind declaration matching (#606, #473) #625, Hosted gem redirect breaks a multi-linegemdeclaration (the Gemfile stops parsing) and drops a trailingif/unlessmodifier #340 → Fix hosted gem redirect breaking multi-line and conditional gem lines (#340) #637, vlt lock inventory and hosted restore resolve a node's registry differently #562 → Resolve vlt registry bases through one shared function (#562) #574, Patch blob and diff downloads buffer the whole response body with no size cap #571 → Stream patch blob and diff downloads to disk (#571) #607, Gem settings resolution skips Bundler's global config (~/.bundle/config/BUNDLE_USER_CONFIG), so a globalcache_pathorgemfilegets no warning or refusal and VEX attests an unpatched install #577 → Fix Bundler global config being ignored (#577) #621, npm vendored vex and vendor --check pass while a second registry copy of the patched package@version in the same package-lock.json stays unwired and installs unpatched #588 → Fix npm/Bun VEX attesting a patch a same-lock copy skips (#588) #589, Hosted scan/get run from a pnpm workspace member (or withlockfile-dir=..) ignores the parent pnpm-lock.yaml and reports success while pinning nothing #590 and Hosted cargo scan run from a workspace member treats it as a lockless project, rewrites only the member, and breaks every build of the workspace while reporting success #417 → Fix hosted scan from a workspace member pinning nothing or the wrong files (#590, #417) #598, NuGet and Cargo crawlers hang on a FIFO at obj/project.assets.json or vendor/<crate>/Cargo.toml #592 → Read NuGet and Cargo crawler project files through the FIFO-safe reader (#592) #602, Agent-mode apply skips a bundled copy inside another vlt/pnpm store entry whenever the package is also installed normally, and VEX attests not_affected #601 and Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603 → Fix npm store copies missed by agent apply and vex (#601, #603) #605, PDM PEP 582 detection missespython.use_venv = falseas PDM 2.27+ writes it (a TOML string) and in the user config, so agent mode patches an activated or stray venv and leaves__pypackages__unpatched #609 and Global scan (-g) ignores PDM's site-wide config, so a global project relocated in /etc/xdg/pdm/config.toml is never crawled and get -g reports "applied" while the copy PDM runs stays unpatched #566 → Fix PDM settings ignoring PDM's config layers (#609, #566) #611, Vendored Hatch runs ahatchexecutable planted in the scanned project #613 → Fix vendored Hatch running a planted hatch (#613) #617, Hatch hosted→vendored takeover with two or more patches leaves allow-direct-references = true (plus empty [tool]/[tool.hatch] tables) behind after rollback or remove, disabling Hatchling's direct-reference guard #674 → Fix Hatch takeover leaving direct-ref permission (#674) #680, Hosted gem redirect ignores Bundler'smirror.allsetting, so the nextbundle installfetches the redirected gem's upstream bytes from the mirror while the in-run VEX attestsnot_affected#681 → Fix hosted gem redirect ignoring Bundler mirror.all (#681) #684, Afteryarn removeof a vendored package, rollback fails forever (exit 1) and no command can clean up the orphaned yarn classic artifact; the remedies it prints don't work #665 → Fix vendored revert keeping artifact for removed lock entry (#665) #689.--vexstill attests the bundled purl). It is claimed with open draft PR Fix in-run hosted VEX attesting npm bundled copies (#325) #669, so it stays open.pm:*label; it isn't a bughunt issue, so the janitor leaves labelling to triage.Needs a human
is_bundled_entrycalled before the spec compare), so the janitor did not close it. A human should decide whether the same reasoning applies.vexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 (closed by Fix agent vex checking only one installed copy (#516) #517 while Deno_1copies are still missed) now has a Deno follow-up: Agent-mode vex still attests not_affected when a Deno.deno/<name>@<ver>_1copy is unpatched: the #517 every-copy check never sees store peer-variant copies #603. A human can drop this item unless they want Agent-mode npmvexhashes only the first installed copy of a package, so it attests not_affected while another nested copy of the same name@version is unpatched #516 reopened instead.janitor/ledgerbranch requires signed commits. Pushes signed with the default session identity work, but pushes made under a customuser.name/user.emailare rejected (GH013).Generated by Claude Code
All reactions