Skip to content

Releases: amarjaleelbanbhan/VeriPatch

v0.3.1

Choose a tag to compare

@github-actions github-actions released this 04 Jul 20:01
c541aab

Patch Changes

  • 6ef84b7 Thanks @amarjaleelbanbhan! - Fix a pnpm lockfile parsing bug: a package whose peer dependency itself has a peer suffix
    (e.g. @eslint-community/eslint-utils@4.9.1(eslint@9.39.4(jiti@1.21.7)) — extremely common in
    real-world ESLint 9 projects) was rejected with "invalid npm package name". The parser used
    lastIndexOf('@') on the raw lockfile key to split package name from version, which broke as
    soon as the nested peer suffix contained its own @. It now strips the peer suffix first
    (respecting nesting), then splits name from version.

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 04 Jul 06:37
4112658

Minor Changes

  • adba3ed Thanks @amarjaleelbanbhan! - Redesigned veripatch scan and veripatch verify terminal output to the polish level of
    modern developer tools. scan now shows a brand header, a Project Summary card (package
    manager, packages scanned, vulnerabilities, verified fixes, manual review), a ranked Top
    Vulnerabilities table (package, severity, current version, safe version, verification status),
    a Verification section that explains each real verdict in plain language, and a final
    recommendation box. A progress spinner narrates the real scan phases. Everything is built on a
    zero-dependency UI toolkit that measures by visible width (perfect alignment even with color),
    auto-detects terminal width, degrades to ASCII where Unicode isn't supported, and emits zero
    escape codes when piped to a file or a non-TTY (NO_COLOR / FORCE_COLOR honored). --json
    output is unchanged.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 04 Jul 04:39
5ea1a9d

Minor Changes

  • 140144c Thanks @amarjaleelbanbhan! - New veripatch baseline list|add|remove|prune subcommands manage accepted debt one finding at
    a time: add records a reason and an optional expiry (--expires-days), after which the vuln
    counts as new again in scan --ci; prune drops entries whose vulns no longer appear in the
    last scan. baseline.json gains optional per-entry metadata, additively — existing files keep
    working unchanged.

  • 281d079 Thanks @amarjaleelbanbhan! - npm workspaces are now scanned correctly from the monorepo root: workspace members'
    dependencies (including cross-workspace references through link entries) appear in the graph
    with provenance chains that name the owning workspace, e.g. root > @ws/lib > vulnerable-dep.
    Workspace members themselves are never reported as vulnerabilities — they are first-party code.

  • 6f297e4 Thanks @amarjaleelbanbhan! - Transitive-dependency fixes are now applied the way a human would commit them: both the verify
    sandbox and veripatch update write an npm overrides entry and regenerate the lockfile,
    instead of running npm install pkg@to — which would have added the package as a new root
    dependency. Direct dependencies keep the plain versioned install.

  • 10feb88 Thanks @amarjaleelbanbhan! - verify --all can run sandbox verifications in parallel: new verifyConcurrency config key
    (default 1, max 8) and --concurrency flag. Each verification keeps its own container,
    network, and staging copy; per-candidate output is buffered and printed in input order, so the
    transcript stays deterministic regardless of which sandbox finishes first.

  • 6872cbf Thanks @amarjaleelbanbhan! - scan now supports pnpm projects: pnpm-lock.yaml v6 (pnpm 8) and v9 (pnpm 9+) are parsed
    into the same dependency graph as npm and yarn lockfiles, with peer-resolution suffixes merged
    into one node per package version. Lockfile auto-detection covers all three managers (npm →
    yarn → pnpm precedence, with a warning naming any ignored lockfile). verify and update
    refuse pnpm projects explicitly for now, matching the yarn behavior.

  • c78b9cb Thanks @amarjaleelbanbhan! - scan now supports yarn projects: both classic (v1) and berry (v2+) yarn.lock files are
    parsed into the same dependency graph as npm lockfiles, with auto-detection when multiple
    lockfiles coexist (package-lock.json wins, with a warning). Reports gain a packageManager
    field. verify and update refuse yarn projects explicitly for now — they replay fixes with
    npm, and silently writing a package-lock.json into a yarn project would corrupt it.

veripatch@0.3.1

Choose a tag to compare

@github-actions github-actions released this 04 Jul 20:01
c541aab

See CHANGELOG.md for details.

veripatch@0.3.0

Choose a tag to compare

@github-actions github-actions released this 04 Jul 06:37
4112658

See CHANGELOG.md for details.

veripatch@0.2.0

Choose a tag to compare

@github-actions github-actions released this 04 Jul 04:39
5ea1a9d

See CHANGELOG.md for details.

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 03 Jul 21:58

Patch Changes

  • e31cfad Thanks @amarjaleelbanbhan! - Fix a critical bug where the CLI silently did nothing (exit 0, no output) when invoked through a globally-installed npm symlink on Linux/macOS -- the vast majority of real installs. veripatch scan, veripatch --version, and every other command were affected. Windows was unaffected (npm generates a .cmd wrapper there instead of a symlink), which is why this went unnoticed until a real end-to-end test against the published package on a Linux CI runner.

v0.1.0

Choose a tag to compare

@amarjaleelbanbhan amarjaleelbanbhan released this 03 Jul 18:11

Initial release. From here on, CHANGELOG.md is maintained by changesets — every subsequent entry is generated from PR-attached changesets, not written by hand.

Added

  • scan — parses package-lock.json (v2/v3, with a degraded package.json-only fallback), fetches advisories from OSV.dev (SQLite-cached, TTL-based, offline stale-serve), ranks vulnerabilities by severity, and resolves a deterministic fix per vuln (direct bump for a direct dependency, npm overrides for a transitive one). --ci mode diffs against a committed baseline.json (--write-baseline to create one) so pre-existing debt doesn't fail builds.
  • verify — applies a candidate fix inside a hardened Docker sandbox (non-root, all capabilities dropped, no-new-privileges, resource-limited, network-phased: registry-only during install, fully isolated for build/test), re-scans the bumped lockfile to prove the vulnerability is actually gone, and computes a deterministic HIGH/MEDIUM/FAIL/INCONCLUSIVE confidence verdict from exit codes and the rescan alone — never from log-text heuristics.
  • report — re-renders report.json / report.md / a GitHub-flavored pr-comment from stored run artifacts, without re-running scan or verify.
  • update — applies a verified fix to the real working tree, refusing unless the verification confidence is HIGH/MEDIUM and the git tree is clean (both overridable). Never commits or pushes.
  • doctor — diagnoses Node version, Docker reachability, sandbox image pullability, lockfile presence, OSV.dev reachability, cache writability, and config validity.
  • cache clear/cache stats — manage the local advisory cache.
  • A composite GitHub Action (action.yml) wrapping scan/verify with inline annotations, an uploaded report.json artifact, and an optional sticky PR comment.

Security

  • Every sandboxed install runs npm ci --ignore-scripts — the primary defense against a malicious postinstall script, since the network-phase boundary alone constrains which network the container is on, not which domains it can reach. See docs/SECURITY.md for the full threat model and documented residual risks.

Note on npm publish

The CLI's npm package (veripatch) has not been published to the npm registry yet — that needs a one-time OIDC trusted-publisher setup on npm's side. The published GitHub Action can already be referenced by tag: uses: amarjaleelbanbhan/VeriPatch@v0.1.0.

Full Changelog: https://github.com/amarjaleelbanbhan/VeriPatch/commits/v0.1.0

veripatch@0.1.1

Choose a tag to compare

@github-actions github-actions released this 03 Jul 21:58

See CHANGELOG.md for details.