Releases: amarjaleelbanbhan/VeriPatch
Release list
v0.3.1
Patch Changes
6ef84b7Thanks @amarjaleelbanbhan! - Fix a pnpm lockfile parsing bug: a package whose peer dependency itself has a peer suffix
(e.g.@eslint-community/eslint-utils@4.9.1(eslint@9.39.4(jiti@1.21.7))— extremely common in
real-world ESLint 9 projects) was rejected with "invalid npm package name". The parser used
lastIndexOf('@')on the raw lockfile key to split package name from version, which broke as
soon as the nested peer suffix contained its own@. It now strips the peer suffix first
(respecting nesting), then splits name from version.
v0.3.0
Minor Changes
adba3edThanks @amarjaleelbanbhan! - Redesignedveripatch scanandveripatch verifyterminal output to the polish level of
modern developer tools.scannow shows a brand header, a Project Summary card (package
manager, packages scanned, vulnerabilities, verified fixes, manual review), a ranked Top
Vulnerabilities table (package, severity, current version, safe version, verification status),
a Verification section that explains each real verdict in plain language, and a final
recommendation box. A progress spinner narrates the real scan phases. Everything is built on a
zero-dependency UI toolkit that measures by visible width (perfect alignment even with color),
auto-detects terminal width, degrades to ASCII where Unicode isn't supported, and emits zero
escape codes when piped to a file or a non-TTY (NO_COLOR/FORCE_COLORhonored).--json
output is unchanged.
v0.2.0
Minor Changes
-
140144cThanks @amarjaleelbanbhan! - Newveripatch baseline list|add|remove|prunesubcommands manage accepted debt one finding at
a time:addrecords a reason and an optional expiry (--expires-days), after which the vuln
counts as new again inscan --ci;prunedrops entries whose vulns no longer appear in the
last scan.baseline.jsongains optional per-entry metadata, additively — existing files keep
working unchanged. -
281d079Thanks @amarjaleelbanbhan! - npm workspaces are now scanned correctly from the monorepo root: workspace members'
dependencies (including cross-workspace references through link entries) appear in the graph
with provenance chains that name the owning workspace, e.g.root > @ws/lib > vulnerable-dep.
Workspace members themselves are never reported as vulnerabilities — they are first-party code. -
6f297e4Thanks @amarjaleelbanbhan! - Transitive-dependency fixes are now applied the way a human would commit them: both the verify
sandbox andveripatch updatewrite an npmoverridesentry and regenerate the lockfile,
instead of runningnpm install pkg@to— which would have added the package as a new root
dependency. Direct dependencies keep the plain versioned install. -
10feb88Thanks @amarjaleelbanbhan! -verify --allcan run sandbox verifications in parallel: newverifyConcurrencyconfig key
(default 1, max 8) and--concurrencyflag. Each verification keeps its own container,
network, and staging copy; per-candidate output is buffered and printed in input order, so the
transcript stays deterministic regardless of which sandbox finishes first. -
6872cbfThanks @amarjaleelbanbhan! -scannow supports pnpm projects:pnpm-lock.yamlv6 (pnpm 8) and v9 (pnpm 9+) are parsed
into the same dependency graph as npm and yarn lockfiles, with peer-resolution suffixes merged
into one node per package version. Lockfile auto-detection covers all three managers (npm →
yarn → pnpm precedence, with a warning naming any ignored lockfile).verifyandupdate
refuse pnpm projects explicitly for now, matching the yarn behavior. -
c78b9cbThanks @amarjaleelbanbhan! -scannow supports yarn projects: both classic (v1) and berry (v2+)yarn.lockfiles are
parsed into the same dependency graph as npm lockfiles, with auto-detection when multiple
lockfiles coexist (package-lock.jsonwins, with a warning). Reports gain apackageManager
field.verifyandupdaterefuse yarn projects explicitly for now — they replay fixes with
npm, and silently writing apackage-lock.jsoninto a yarn project would corrupt it.
veripatch@0.3.1
See CHANGELOG.md for details.
veripatch@0.3.0
See CHANGELOG.md for details.
veripatch@0.2.0
See CHANGELOG.md for details.
v0.1.1
Patch Changes
e31cfadThanks @amarjaleelbanbhan! - Fix a critical bug where the CLI silently did nothing (exit 0, no output) when invoked through a globally-installed npm symlink on Linux/macOS -- the vast majority of real installs.veripatch scan,veripatch --version, and every other command were affected. Windows was unaffected (npm generates a.cmdwrapper there instead of a symlink), which is why this went unnoticed until a real end-to-end test against the published package on a Linux CI runner.
v0.1.0
Initial release. From here on, CHANGELOG.md is maintained by changesets — every subsequent entry is generated from PR-attached changesets, not written by hand.
Added
scan— parsespackage-lock.json(v2/v3, with a degraded package.json-only fallback), fetches advisories from OSV.dev (SQLite-cached, TTL-based, offline stale-serve), ranks vulnerabilities by severity, and resolves a deterministic fix per vuln (direct bump for a direct dependency,npm overridesfor a transitive one).--cimode diffs against a committedbaseline.json(--write-baselineto create one) so pre-existing debt doesn't fail builds.verify— applies a candidate fix inside a hardened Docker sandbox (non-root, all capabilities dropped,no-new-privileges, resource-limited, network-phased: registry-only during install, fully isolated for build/test), re-scans the bumped lockfile to prove the vulnerability is actually gone, and computes a deterministicHIGH/MEDIUM/FAIL/INCONCLUSIVEconfidence verdict from exit codes and the rescan alone — never from log-text heuristics.report— re-rendersreport.json/report.md/ a GitHub-flavoredpr-commentfrom stored run artifacts, without re-running scan or verify.update— applies a verified fix to the real working tree, refusing unless the verification confidence isHIGH/MEDIUMand the git tree is clean (both overridable). Never commits or pushes.doctor— diagnoses Node version, Docker reachability, sandbox image pullability, lockfile presence, OSV.dev reachability, cache writability, and config validity.cache clear/cache stats— manage the local advisory cache.- A composite GitHub Action (
action.yml) wrappingscan/verifywith inline annotations, an uploadedreport.jsonartifact, and an optional sticky PR comment.
Security
- Every sandboxed install runs
npm ci --ignore-scripts— the primary defense against a maliciouspostinstallscript, since the network-phase boundary alone constrains which network the container is on, not which domains it can reach. See docs/SECURITY.md for the full threat model and documented residual risks.
Note on npm publish
The CLI's npm package (veripatch) has not been published to the npm registry yet — that needs a one-time OIDC trusted-publisher setup on npm's side. The published GitHub Action can already be referenced by tag: uses: amarjaleelbanbhan/VeriPatch@v0.1.0.
Full Changelog: https://github.com/amarjaleelbanbhan/VeriPatch/commits/v0.1.0
veripatch@0.1.1
See CHANGELOG.md for details.