Skip to content

馃摚馃 feat(fix): add opt-in --allow-overrides flag - #1573

Draft
Martin Torp (mtorp) wants to merge 1 commit into
v1.xfrom
martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing
Draft

Martin Torp (mtorp) wants to merge 1 commit into
v1.xfrom
martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing

Conversation

@mtorp

@mtorp Martin Torp (mtorp) commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

LLM Description written by claude-code:claude-opus-5-5

Summary

This adds an opt-in --allow-overrides flag to socket fix. It is off by default.

Sometimes the only fix for a vulnerability is blocked because a parent package declares a version range that rules out every fixed version. With the flag set, Coana writes an override or resolution that forces the fixed version under that parent. That is an npm overrides, pnpm overrides, Yarn Berry resolutions or Rush globalOverrides entry. The forced version can sit outside the range the parent declares, so the help text tells people to test the parent afterwards.

The CLI passes --allow-overrides to compute-fixes-and-upgrade-purls in both local mode and CI/PR mode. It only passes it when the flag is set, so runs keep working with the pinned Coana version, which does not know the flag yet.

Why

Part of ENG-5422, this PR is ENG-5425. The fix engine side is SocketDev/depscan#27205, which adds allow_overrides to the /fixes API. The Coana CLI side, coana-tech/coana-package-manager#2525, adds --allow-overrides to compute-fixes-and-upgrade-purls.

Testing

  • pnpm build:dist:src, then pnpm test:unit src/commands/fix/handle-fix-limit.test.mts src/commands/fix/coana-fix-pr-files.test.mts src/commands/fix/coana-fix-dynamic-sbom-inference.test.mts src/commands/fix/handle-fix-id.test.mts passes (55 tests). New cases check that the flag reaches Coana in local and PR mode and is left out when unset.
  • pnpm test:unit src/commands/fix/cmd-fix.integration.test.mts: the updated --help snapshot and the new --allow-overrides dry-run case pass. Two other cases fail on my machine (--autopilot --config {} and a 30s timeout in --ecosystems ... --package-managers). They fail the same way on an untouched v1.x checkout, so they are local environment noise.
  • pnpm run check:tsc passes.
  • pnpm run lint passes with 3 existing warnings on lines this PR does not touch.

Follow-ups

  • Bump the pinned @coana-tech/cli once Coana ships a release with --allow-overrides. Until then, setting the flag sends an option the pinned Coana version does not know, so this should merge together with that bump or after it.
  • Document the flag on docs.socket.dev (separate repo).
  • In CI/PR mode, add a note to the fix PR body when the fix wrote an override, so reviewers know to test the parent package.

Expected reviewer effort: Stamp

socket fix can now write a package manager override when that is the
only way to fix a vulnerability. This happens when a parent package
declares a version range that rules out every fixed version of the
vulnerable dependency.

The flag is off by default. When it is set, socket fix passes
--allow-overrides to Coana in both local and CI mode. Coana then writes
an npm overrides, pnpm overrides, Yarn Berry resolutions or Rush
globalOverrides entry scoped to the blocking parent. The forced version
can sit outside the range the parent declares, so the parent should be
tested afterwards.

Coana only gets the flag when it is set, so runs keep working with
Coana versions that do not know it yet.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant