Skip to content

馃摚馃 feat(fix): add opt-in --allow-overrides flag - #1573

Merged
Martin Torp (mtorp) merged 1 commit into
v1.xfrom
martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing
Oct 6, 2026
Merged

Martin Torp (mtorp) merged 1 commit into
v1.xfrom
martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing

Conversation

@mtorp

@mtorp Martin Torp (mtorp) commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

LLM Description written by claude-code:claude-opus-5-5

Summary

This adds an opt-in --allow-overrides flag to socket fix. It is off by default.

Sometimes the only fix for a vulnerability is blocked because a parent package declares a version range that rules out every fixed version. With the flag set, Coana writes an override or resolution that forces the fixed version under that parent. That is an npm overrides, pnpm overrides, Yarn Berry resolutions or Rush globalOverrides entry. The forced version can sit outside the range the parent declares, so the help text tells people to test the parent afterwards.

The CLI passes --allow-overrides to compute-fixes-and-upgrade-purls in both local mode and CI/PR mode. It only passes it when the flag is set, so runs keep working with older Coana versions that do not know the flag. The pinned Coana version (15.12.0) already supports it.

Why

Part of ENG-5422, this PR is ENG-5425. The fix engine side is SocketDev/depscan#27205, which adds allow_overrides to the /fixes API. The Coana CLI side, coana-tech/coana-package-manager#2525, adds --allow-overrides to compute-fixes-and-upgrade-purls.

Testing

  • pnpm build:dist:src, then pnpm test:unit src/commands/fix/handle-fix-limit.test.mts src/commands/fix/coana-fix-pr-files.test.mts src/commands/fix/coana-fix-dynamic-sbom-inference.test.mts src/commands/fix/handle-fix-id.test.mts passes (55 tests). New cases check that the flag reaches Coana in local and PR mode and is left out when unset.
  • pnpm test:unit src/commands/fix/cmd-fix.integration.test.mts: the updated --help snapshot and the new --allow-overrides dry-run case pass. Two other cases fail on my machine (--autopilot --config {} and a 30s timeout in --ecosystems ... --package-managers). They fail the same way on an untouched v1.x checkout, so they are local environment noise.
  • pnpm run check:tsc passes.
  • pnpm run lint passes with 3 existing warnings on lines this PR does not touch.

Follow-ups

  • Document the flag on docs.socket.dev (separate repo).
  • In CI/PR mode, add a note to the fix PR body when the fix wrote an override, so reviewers know to test the parent package.

Expected reviewer effort: Stamp


Note

Medium Risk
Opt-in, but when used it can change lockfiles and manifest overrides to install versions outside a parent鈥檚 declared range, which can break runtime compatibility if not validated.

Overview
Adds an opt-in --allow-overrides flag to socket fix (default off). When enabled, the CLI forwards --allow-overrides to Coana鈥檚 compute-fixes-and-upgrade-purls in both local fix runs and CI/PR mode so fixes blocked by a parent鈥檚 version range can use npm/pnpm/Yarn Berry/Rush overrides or resolutions.

The flag is wired from cmd-fix through handleFix / FixConfig into coana-fix, with help text and CHANGELOG noting that forced versions may sit outside the parent鈥檚 declared range. Tests cover CLI acceptance, help output, and that the flag is passed to Coana only when set.

Reviewed by Cursor Bugbot for commit 75c4f3b. Configure here.

socket fix can now write a package manager override when that is the
only way to fix a vulnerability. This happens when a parent package
declares a version range that rules out every fixed version of the
vulnerable dependency.

The flag is off by default. When it is set, socket fix passes
--allow-overrides to Coana in both local and CI mode. Coana then writes
an npm overrides, pnpm overrides, Yarn Berry resolutions or Rush
globalOverrides entry scoped to the blocking parent. The forced version
can sit outside the range the parent declares, so the parent should be
tested afterwards.

Coana only gets the flag when it is set, so runs keep working with
Coana versions that do not know it yet.
@mtorp
Martin Torp (mtorp) force-pushed the martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing branch from f7b0579 to 75c4f3b Compare October 6, 2026 07:17
@mtorp
Martin Torp (mtorp) marked this pull request as ready for review October 6, 2026 07:17
@mtorp
Martin Torp (mtorp) merged commit e72091c into v1.x Oct 6, 2026
16 checks passed
@mtorp
Martin Torp (mtorp) deleted the martin/eng-5425-socket-cli-add-opt-in-flag-to-socket-fix-for-writing branch October 6, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants