馃摚馃 feat(fix): add opt-in --allow-overrides flag - #1573
Merged
Martin Torp (mtorp) merged 1 commit intoOct 6, 2026
Merged
Martin Torp (mtorp) merged 1 commit into
Martin Torp (mtorp) merged 1 commit into
Conversation
socket fix can now write a package manager override when that is the only way to fix a vulnerability. This happens when a parent package declares a version range that rules out every fixed version of the vulnerable dependency. The flag is off by default. When it is set, socket fix passes --allow-overrides to Coana in both local and CI mode. Coana then writes an npm overrides, pnpm overrides, Yarn Berry resolutions or Rush globalOverrides entry scoped to the blocking parent. The forced version can sit outside the range the parent declares, so the parent should be tested afterwards. Coana only gets the flag when it is set, so runs keep working with Coana versions that do not know it yet.
Martin Torp (mtorp)
force-pushed
the
martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing
branch
from
October 6, 2026 07:17
f7b0579 to
75c4f3b
Compare
Martin Torp (mtorp)
marked this pull request as ready for review
October 6, 2026 07:17
Martin Torp (mtorp)
requested a review
from Benjamin Barslev Nielsen (barslev)
October 6, 2026 07:18
Benjamin Barslev Nielsen (barslev)
approved these changes
Oct 6, 2026
Martin Torp (mtorp)
deleted the
martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing
branch
October 6, 2026 07:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by claude-code:claude-opus-5-5
Summary
This adds an opt-in
--allow-overridesflag tosocket fix. It is off by default.Sometimes the only fix for a vulnerability is blocked because a parent package declares a version range that rules out every fixed version. With the flag set, Coana writes an override or resolution that forces the fixed version under that parent. That is an npm
overrides, pnpm overrides, Yarn Berryresolutionsor RushglobalOverridesentry. The forced version can sit outside the range the parent declares, so the help text tells people to test the parent afterwards.The CLI passes
--allow-overridestocompute-fixes-and-upgrade-purlsin both local mode and CI/PR mode. It only passes it when the flag is set, so runs keep working with older Coana versions that do not know the flag. The pinned Coana version (15.12.0) already supports it.Why
Part of ENG-5422, this PR is ENG-5425. The fix engine side is SocketDev/depscan#27205, which adds
allow_overridesto the/fixesAPI. The Coana CLI side, coana-tech/coana-package-manager#2525, adds--allow-overridestocompute-fixes-and-upgrade-purls.Testing
pnpm build:dist:src, thenpnpm test:unit src/commands/fix/handle-fix-limit.test.mts src/commands/fix/coana-fix-pr-files.test.mts src/commands/fix/coana-fix-dynamic-sbom-inference.test.mts src/commands/fix/handle-fix-id.test.mtspasses (55 tests). New cases check that the flag reaches Coana in local and PR mode and is left out when unset.pnpm test:unit src/commands/fix/cmd-fix.integration.test.mts: the updated--helpsnapshot and the new--allow-overridesdry-run case pass. Two other cases fail on my machine (--autopilot --config {}and a 30s timeout in--ecosystems ... --package-managers). They fail the same way on an untouchedv1.xcheckout, so they are local environment noise.pnpm run check:tscpasses.pnpm run lintpasses with 3 existing warnings on lines this PR does not touch.Follow-ups
Expected reviewer effort: Stamp
Note
Medium Risk
Opt-in, but when used it can change lockfiles and manifest overrides to install versions outside a parent鈥檚 declared range, which can break runtime compatibility if not validated.
Overview
Adds an opt-in
--allow-overridesflag tosocket fix(default off). When enabled, the CLI forwards--allow-overridesto Coana鈥檚compute-fixes-and-upgrade-purlsin both local fix runs and CI/PR mode so fixes blocked by a parent鈥檚 version range can use npm/pnpm/Yarn Berry/Rush overrides or resolutions.The flag is wired from
cmd-fixthroughhandleFix/FixConfigintocoana-fix, with help text and CHANGELOG noting that forced versions may sit outside the parent鈥檚 declared range. Tests cover CLI acceptance, help output, and that the flag is passed to Coana only when set.Reviewed by Cursor Bugbot for commit 75c4f3b. Configure here.