Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,11 @@ All notable changes to this project will be documented in this file.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).

## [Unreleased]

### Added
- `socket fix --allow-overrides` fixes a vulnerability that a parent package's version range blocks by writing an override or resolution that forces the fixed version under that parent, in npm, pnpm, Yarn Berry and Rush projects.

## [1.4.1](https://github.com/SocketDev/socket-cli/releases/tag/v1.4.1) - 2026-09-30

### Changed
Expand Down
17 changes: 17 additions & 0 deletions src/commands/fix/cmd-fix.integration.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,7 @@ describe('socket fix', async () => {

Options
--all Process all discovered vulnerabilities in local mode. Cannot be used with --id.
--allow-overrides When the only fix for a vulnerability is blocked by a parent package's declared version range, write an override or resolution that forces the fixed version under that parent. This can install a version outside the range the parent declares, so test the parent afterwards. Works for npm, pnpm, Yarn Berry and Rush projects.
--autopilot Enable auto-merge for pull requests that Socket opens.
See GitHub documentation (https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/configuring-pull-request-merges/managing-auto-merge-for-pull-requests-in-your-repository) for managing auto-merge for pull requests in your repository.
--debug Enable debug logging in the Coana-based Socket Fix CLI invocation.
Expand Down Expand Up @@ -398,6 +399,22 @@ describe('socket fix', async () => {
},
)

cmdit(
[
'fix',
FLAG_DRY_RUN,
'--allow-overrides',
FLAG_CONFIG,
'{"apiToken":"fakeToken"}',
],
'should accept --allow-overrides flag',
async cmd => {
const { code, stdout } = await spawnSocketCli(binCliPath, cmd)
expect(stdout).toMatchInlineSnapshot(`"[DryRun]: Not saving"`)
expect(code, 'should exit with code 0').toBe(0)
},
)

cmdit(
[
'fix',
Expand Down
9 changes: 9 additions & 0 deletions src/commands/fix/cmd-fix.mts
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,12 @@ export const cmdFix = {
}

const generalFlags: MeowFlags = {
allowOverrides: {
type: 'boolean',
default: false,
description:
"When the only fix for a vulnerability is blocked by a parent package's declared version range, write an override or resolution that forces the fixed version under that parent. This can install a version outside the range the parent declares, so test the parent afterwards. Works for npm, pnpm, Yarn Berry and Rush projects.",
},
autopilot: {
type: 'boolean',
default: false,
Expand Down Expand Up @@ -327,6 +333,7 @@ async function run(

const {
all,
allowOverrides,
applyFixes,
autopilot,
debug,
Expand Down Expand Up @@ -354,6 +361,7 @@ async function run(
unknownFlags = [],
} = cli.flags as {
all: boolean
allowOverrides: boolean
applyFixes: boolean
autopilot: boolean
debug: boolean
Expand Down Expand Up @@ -520,6 +528,7 @@ async function run(

await handleFix({
all,
allowOverrides,
applyFixes,
autopilot,
coanaVersion: fixVersion,
Expand Down
1 change: 1 addition & 0 deletions src/commands/fix/coana-fix-dynamic-sbom-inference.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,7 @@ function coanaCalls(command: string): string[][] {
describe('socket fix --dynamic-sbom-inference', () => {
const baseConfig: FixConfig = {
all: false,
allowOverrides: false,
applyFixes: true,
autopilot: false,
coanaVersion: undefined,
Expand Down
1 change: 1 addition & 0 deletions src/commands/fix/coana-fix-pr-files.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,7 @@ function committedFiles(): string[] {
describe('socket fix PR mode commits', () => {
const baseConfig: FixConfig = {
all: false,
allowOverrides: false,
applyFixes: true,
autopilot: false,
coanaVersion: undefined,
Expand Down
3 changes: 3 additions & 0 deletions src/commands/fix/coana-fix.mts
Original file line number Diff line number Diff line change
Expand Up @@ -276,6 +276,7 @@ async function coanaFixWithFacts(
): Promise<CoanaFixResult> {
const {
all,
allowOverrides,
applyFixes,
autopilot,
coanaVersion,
Expand Down Expand Up @@ -522,6 +523,7 @@ async function coanaFixWithFacts(
? ['--disable-external-tool-checks']
: []),
...(disableMajorUpdates ? ['--disable-major-updates'] : []),
...(allowOverrides ? ['--allow-overrides'] : []),
...(showAffectedDirectDependencies
? ['--show-affected-direct-dependencies']
: []),
Expand Down Expand Up @@ -699,6 +701,7 @@ async function coanaFixWithFacts(
? ['--disable-external-tool-checks']
: []),
...(disableMajorUpdates ? ['--disable-major-updates'] : []),
...(allowOverrides ? ['--allow-overrides'] : []),
...(showAffectedDirectDependencies
? ['--show-affected-direct-dependencies']
: []),
Expand Down
61 changes: 61 additions & 0 deletions src/commands/fix/handle-fix-limit.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,7 @@ function mockDiscoveryEnvelope(envelope: {
describe('socket fix --pr-limit behavior verification', () => {
const baseConfig: FixConfig = {
all: false,
allowOverrides: false,
applyFixes: true,
autopilot: false,
coanaVersion: undefined,
Expand Down Expand Up @@ -691,4 +692,64 @@ describe('socket fix --pr-limit behavior verification', () => {
])
})
})

describe('--allow-overrides flag', () => {
it('forwards --allow-overrides to coana in local mode', async () => {
mockSpawnCoanaDlx.mockResolvedValue({ ok: true, data: 'fix applied' })

await coanaFix({
...baseConfig,
allowOverrides: true,
ghsas: ['GHSA-1111-1111-1111'],
})

expect(mockSpawnCoanaDlx).toHaveBeenCalledTimes(1)
const callArgs = mockSpawnCoanaDlx.mock.calls[0]?.[0] as string[]
expect(callArgs[0]).toBe('compute-fixes-and-upgrade-purls')
expect(callArgs).toContain('--allow-overrides')
})

it('omits --allow-overrides when the flag is not set', async () => {
mockSpawnCoanaDlx.mockResolvedValue({ ok: true, data: 'fix applied' })

await coanaFix({
...baseConfig,
ghsas: ['GHSA-1111-1111-1111'],
})

expect(mockSpawnCoanaDlx).toHaveBeenCalledTimes(1)
const callArgs = mockSpawnCoanaDlx.mock.calls[0]?.[0] as string[]
expect(callArgs).not.toContain('--allow-overrides')
})

it('forwards --allow-overrides to coana in PR mode', async () => {
mockGetFixEnv.mockResolvedValue({
baseBranch: 'main',
githubToken: 'test-token',
gitEmail: '[email protected]',
gitUser: 'test-user',
isCi: true,
repoInfo: {
defaultBranch: 'main',
owner: 'test-owner',
repo: 'test-repo',
},
})
mockGetSocketFixPrs.mockResolvedValue([])
mockFetchGhsaDetails.mockResolvedValue(new Map())
mockSpawnCoanaDlx.mockResolvedValue({ ok: true, data: 'fix applied' })

await coanaFix({
...baseConfig,
allowOverrides: true,
ghsas: ['GHSA-1111-1111-1111'],
})

expect(mockSpawnCoanaDlx).toHaveBeenCalledTimes(1)
const callArgs = mockSpawnCoanaDlx.mock.calls[0]?.[0] as string[]
expect(callArgs[0]).toBe('compute-fixes-and-upgrade-purls')
expect(callArgs).toContain('GHSA-1111-1111-1111')
expect(callArgs).toContain('--allow-overrides')
})
})
})
3 changes: 3 additions & 0 deletions src/commands/fix/handle-fix.mts
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,7 @@ export async function convertIdsToGhsas(

export async function handleFix({
all,
allowOverrides,
applyFixes,
autopilot,
coanaVersion,
Expand Down Expand Up @@ -145,6 +146,7 @@ export async function handleFix({
debugFn('notice', `Starting fix command for ${orgSlug}`)
debugDir('inspect', {
all,
allowOverrides,
applyFixes,
autopilot,
coanaVersion,
Expand Down Expand Up @@ -174,6 +176,7 @@ export async function handleFix({
await outputFixResult(
await coanaFix({
all,
allowOverrides,
applyFixes,
autopilot,
coanaVersion,
Expand Down
1 change: 1 addition & 0 deletions src/commands/fix/types.mts
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import type { Spinner } from '@socketsecurity/registry/lib/spinner'

export type FixConfig = {
all: boolean
allowOverrides: boolean
applyFixes: boolean
autopilot: boolean
coanaVersion: string | undefined
Expand Down
Loading