Skip to content

Commit d702d51

Browse files
committed
Fix VEX missing mirrors without gem candidates
Detect Bundler mirrors independently of gem candidates to prevent false attestations when VEX rediscovers lockfile-pinned gems that would be mirrored to unpatched upstream bytes.
1 parent cb0fd60 commit d702d51

1 file changed

Lines changed: 19 additions & 4 deletions

File tree

  • crates/socket-patch-cli/src/commands/scan

‎crates/socket-patch-cli/src/commands/scan/hosted.rs‎

Lines changed: 19 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1253,10 +1253,25 @@ pub(crate) async fn run_redirect_selected(
12531253
// rediscovers older pins too, so a candidate-only set would miss some
12541254
// refused hosted gems. Keep their actual installed-byte verification,
12551255
// but do not infer applied status from the intercepted source.
1256-
params.hosted_gem_mirror_refused = rewrite
1257-
.warnings
1258-
.iter()
1259-
.any(|warning| warning.code == "redirect_gem_mirror_overrides_source");
1256+
// Check for mirrors independently of whether gem candidates are
1257+
// present: a lockfile-discovered gem pin can still be affected by a
1258+
// capturing mirror even when this run has no gem grants. Probe for
1259+
// mirror.all and hostname/exact-source mirrors that would capture the
1260+
// patch registry, using a representative source URL.
1261+
params.hosted_gem_mirror_refused = {
1262+
let patch_registry_sources = &["https://patch.socket.dev/gem/"];
1263+
let mirror_detected = socket_patch_core::crawlers::ruby_crawler::bundler_source_mirror(
1264+
&common.cwd,
1265+
patch_registry_sources,
1266+
)
1267+
.await
1268+
.is_some();
1269+
mirror_detected
1270+
|| rewrite
1271+
.warnings
1272+
.iter()
1273+
.any(|warning| warning.code == "redirect_gem_mirror_overrides_source")
1274+
};
12601275
// Stale-flagged purls are EXCLUDED from assume_applied: the same-run
12611276
// envelope carries a redirect_gem_stale_install warning proving the
12621277
// installed materialization unpatched, so attesting that purl from

0 commit comments

Comments
 (0)