{"_id":"@socketsecurity/socket-patch","_rev":"13-0884533616e0012b8a1f76681f3fa390","name":"@socketsecurity/socket-patch","dist-tags":{"latest":"4.0.0"},"versions":{"0.1.0":{"name":"@socketsecurity/socket-patch","version":"0.1.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@0.1.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"bin":{"socket-patch":"dist/cli.js"},"dist":{"shasum":"cd512076f69221ac7f0629f70c370f2982683c56","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-0.1.0.tgz","fileCount":25,"integrity":"sha512-KJM1O3/dNtLXrpvN8C7hFz0aLDF9JfeUO7H6zpo7RxYgEaY10kbzRCXadFPdPKPq8c2Qo3NFOu4oJCIcVyUi7Q==","signatures":[{"sig":"MEQCIFrbHsZTqCjRo5qBktAJs3izZjVaWpFc9YYJOU5Viiz7AiBgx0Ib7GxeAq22wYEjaKaclLAI1efSCCh3IoirdeaLYg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":62427},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.js"},"./hash":{"types":"./dist/hash/git-sha256.d.ts","import":"./dist/hash/git-sha256.js","require":"./dist/hash/git-sha256.js"},"./patch":{"types":"./dist/patch/apply.d.ts","import":"./dist/patch/apply.js","require":"./dist/patch/apply.js"},"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"},"./constants":{"types":"./dist/constants.d.ts","import":"./dist/constants.js","require":"./dist/constants.js"},"./manifest/recovery":{"types":"./dist/manifest/recovery.d.ts","import":"./dist/manifest/recovery.js","require":"./dist/manifest/recovery.js"},"./manifest/operations":{"types":"./dist/manifest/operations.d.ts","import":"./dist/manifest/operations.js","require":"./dist/manifest/operations.js"}},"gitHead":"ab67f1a93e0690b36446267907758336b3ea24ce","scripts":{"dev":"tsc --watch","lint":"oxlint -c ./.oxlintrc.json --tsconfig ./tsconfig.json --deny-warnings","build":"tsc","patch":"node dist/cli.js","lint:fix":"pnpm run lint --fix && pnpm run lint:fix:fast","publish:ci":"npm publish --provenance --access public","lint:fix:fast":"biome format --write"},"_npmUser":{"name":"socket-bot","email":"eng@socket.dev"},"_npmVersion":"10.9.3","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.20.0","dependencies":{"zod":"^3.24.4","yargs":"^17.7.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.16.1","devDependencies":{"oxlint":"^1.15.0","typescript":"^5.3.0","@types/node":"^20.0.0","@types/yargs":"^17.0.32","@biomejs/biome":"^2.1.2"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_0.1.0_1763481556933_0.9347810154920397","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@socketsecurity/socket-patch","version":"0.2.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@0.2.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"dist/cli.js"},"dist":{"shasum":"44c81237b6e5381f765056312cc67d5fa8625662","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-0.2.0.tgz","fileCount":106,"integrity":"sha512-dFQA/jL1hcl0EgZrb0LysgrqiOWl0hZBI3Kz5Ydp5la2l5HZYPmbg3vYxcN06H9npRwhU1OQ+zq4rFQdGSIuhQ==","signatures":[{"sig":"MEUCIG3j8EU3DLDfhO6nTOfvzu8ggpbHmU+OEv7fScT52qEPAiEAqqAUCkwICYB57B//Ya7YjQEqQne1qmIaTYsNS+DRlzU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":259297},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.js"},"./hash":{"types":"./dist/hash/git-sha256.d.ts","import":"./dist/hash/git-sha256.js","require":"./dist/hash/git-sha256.js"},"./patch":{"types":"./dist/patch/apply.d.ts","import":"./dist/patch/apply.js","require":"./dist/patch/apply.js"},"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"},"./constants":{"types":"./dist/constants.d.ts","import":"./dist/constants.js","require":"./dist/constants.js"},"./package-json":{"types":"./dist/package-json/index.d.ts","import":"./dist/package-json/index.js","require":"./dist/package-json/index.js"},"./manifest/recovery":{"types":"./dist/manifest/recovery.d.ts","import":"./dist/manifest/recovery.js","require":"./dist/manifest/recovery.js"},"./manifest/operations":{"types":"./dist/manifest/operations.d.ts","import":"./dist/manifest/operations.js","require":"./dist/manifest/operations.js"}},"gitHead":"1b4f90543b86329ed1d6e297be39253bad63470b","scripts":{"dev":"tsc --watch","lint":"oxlint -c ./.oxlintrc.json --tsconfig ./tsconfig.json --deny-warnings","build":"tsc","patch":"node dist/cli.js","lint:fix":"pnpm run lint --fix && pnpm run lint:fix:fast","publish:ci":"npm publish --provenance --access public","lint:fix:fast":"biome format --write","prepublishOnly":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bf450828-97fb-471f-a7cb-4b0012c7df27"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.7.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^3.24.4","yargs":"^17.7.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.16.1","devDependencies":{"oxlint":"^1.15.0","typescript":"^5.3.0","@types/node":"^20.0.0","@types/yargs":"^17.0.32","@biomejs/biome":"^2.1.2"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_0.2.0_1765395379528_0.7607775867016284","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@socketsecurity/socket-patch","version":"0.2.1","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@0.2.1","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"dist/cli.js"},"dist":{"shasum":"0e8f07cb9a3c0d7cfc57fbee6428d5b3e17d9e37","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-0.2.1.tgz","fileCount":127,"integrity":"sha512-hVdV9t82dhYdRp0Vd33ZzH+USpkKBgnb2QnJPNCsX29pYJ4DTg/KmLiATpQgk7HO833fGIuyAwfVKYFqGWpWwg==","signatures":[{"sig":"MEUCIQCsB71OOEAhEWZNGU1SXFXfzrGzfPrgkt3qAdLNsC3DQQIgO1riLRUWgo7Vyle91N88wggSXEaoCRXx73nmRkwclhU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":350624},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.js"},"./hash":{"types":"./dist/hash/git-sha256.d.ts","import":"./dist/hash/git-sha256.js","require":"./dist/hash/git-sha256.js"},"./patch":{"types":"./dist/patch/apply.d.ts","import":"./dist/patch/apply.js","require":"./dist/patch/apply.js"},"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"},"./constants":{"types":"./dist/constants.d.ts","import":"./dist/constants.js","require":"./dist/constants.js"},"./package-json":{"types":"./dist/package-json/index.d.ts","import":"./dist/package-json/index.js","require":"./dist/package-json/index.js"},"./manifest/recovery":{"types":"./dist/manifest/recovery.d.ts","import":"./dist/manifest/recovery.js","require":"./dist/manifest/recovery.js"},"./manifest/operations":{"types":"./dist/manifest/operations.d.ts","import":"./dist/manifest/operations.js","require":"./dist/manifest/operations.js"}},"gitHead":"e8e36061e09be5d05f69f759117da4fae5dc1868","scripts":{"dev":"tsc --watch","lint":"oxlint -c ./.oxlintrc.json --tsconfig ./tsconfig.json --deny-warnings","test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc","patch":"node dist/cli.js","lint:fix":"pnpm run lint --fix && pnpm run lint:fix:fast","test:unit":"pnpm run build && node --test --test-reporter=spec dist/**/*.test.js","publish:ci":"npm publish --provenance --access public","lint:fix:fast":"biome format --write","prepublishOnly":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bf450828-97fb-471f-a7cb-4b0012c7df27"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.7.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^3.24.4","yargs":"^17.7.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.16.1","devDependencies":{"oxlint":"^1.15.0","typescript":"^5.3.0","@types/node":"^20.0.0","@types/yargs":"^17.0.32","@biomejs/biome":"^2.1.2"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_0.2.1_1765557307333_0.463424847082883","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@socketsecurity/socket-patch","version":"0.3.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@0.3.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"dist/cli.js"},"dist":{"shasum":"082d7b2d8beecf80d199dd61bdb4d89316a2cb88","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-0.3.0.tgz","fileCount":140,"integrity":"sha512-fhelQILFomp3iJkcvNb2adUXSkfobxRXk6Gok0Gt6A2hNfVP8UFSG6JSBwtZnGJMThpg2be31VGuw4pYlbbyRA==","signatures":[{"sig":"MEUCIQDM9BlVTYuxDUD/8iZOTGDUaIwBjGM5UYyww7zhTfVTBwIgLz9htxd0kRFKAbNouY4iRVw8gBvTFltgacN4+V9vG68=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":420944},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.js"},"./hash":{"types":"./dist/hash/git-sha256.d.ts","import":"./dist/hash/git-sha256.js","require":"./dist/hash/git-sha256.js"},"./patch":{"types":"./dist/patch/apply.d.ts","import":"./dist/patch/apply.js","require":"./dist/patch/apply.js"},"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"},"./constants":{"types":"./dist/constants.d.ts","import":"./dist/constants.js","require":"./dist/constants.js"},"./package-json":{"types":"./dist/package-json/index.d.ts","import":"./dist/package-json/index.js","require":"./dist/package-json/index.js"},"./manifest/recovery":{"types":"./dist/manifest/recovery.d.ts","import":"./dist/manifest/recovery.js","require":"./dist/manifest/recovery.js"},"./manifest/operations":{"types":"./dist/manifest/operations.d.ts","import":"./dist/manifest/operations.js","require":"./dist/manifest/operations.js"}},"gitHead":"4bbff484d23f023ec5ac1910797c0de1382d35e6","scripts":{"dev":"tsc --watch","lint":"oxlint -c ./.oxlintrc.json --tsconfig ./tsconfig.json --deny-warnings","test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc","patch":"node dist/cli.js","lint:fix":"pnpm run lint --fix && pnpm run lint:fix:fast","test:unit":"pnpm run build && node --test --test-reporter=spec dist/**/*.test.js","publish:ci":"npm publish --provenance --access public","lint:fix:fast":"biome format --write","prepublishOnly":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bf450828-97fb-471f-a7cb-4b0012c7df27"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.7.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^3.24.4","yargs":"^17.7.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.16.1","devDependencies":{"oxlint":"^1.15.0","typescript":"^5.3.0","@types/node":"^20.0.0","@types/yargs":"^17.0.32","@biomejs/biome":"^2.1.2"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_0.3.0_1766071045247_0.38106558124242396","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@socketsecurity/socket-patch","version":"1.0.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@1.0.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"dist/cli.js"},"dist":{"shasum":"2add3fa31150909da09f97f48a0b374eab6289ae","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-1.0.0.tgz","fileCount":148,"integrity":"sha512-B8kT5DEF7rD97N8UohenFGuqGVlS82RlUwF31yWzzi8bw2YEUM0vxdYE1pZveByd+fexj2zpY8nXK0cKF6+eeQ==","signatures":[{"sig":"MEUCIA4+fIpogA8SY9Zf5/Q4wKnuenOYpkXjwkvAX4IfufDvAiEA/EATmiX3Om+OpZJpGQPuQn2jVDLuzhFinlkuMTUWtG8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":485203},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.js"},"./run":{"types":"./dist/run.d.ts","import":"./dist/run.js","require":"./dist/run.js"},"./hash":{"types":"./dist/hash/git-sha256.d.ts","import":"./dist/hash/git-sha256.js","require":"./dist/hash/git-sha256.js"},"./patch":{"types":"./dist/patch/apply.d.ts","import":"./dist/patch/apply.js","require":"./dist/patch/apply.js"},"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"},"./constants":{"types":"./dist/constants.d.ts","import":"./dist/constants.js","require":"./dist/constants.js"},"./package-json":{"types":"./dist/package-json/index.d.ts","import":"./dist/package-json/index.js","require":"./dist/package-json/index.js"},"./manifest/recovery":{"types":"./dist/manifest/recovery.d.ts","import":"./dist/manifest/recovery.js","require":"./dist/manifest/recovery.js"},"./manifest/operations":{"types":"./dist/manifest/operations.d.ts","import":"./dist/manifest/operations.js","require":"./dist/manifest/operations.js"}},"gitHead":"06d5d8feaf73dca51d47951408ac60b067e62134","scripts":{"dev":"tsc --watch","lint":"oxlint -c ./.oxlintrc.json --tsconfig ./tsconfig.json --deny-warnings","test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc","patch":"node dist/cli.js","lint:fix":"pnpm run lint --fix && pnpm run lint:fix:fast","test:unit":"pnpm run build && node --test --test-reporter=spec dist/**/*.test.js","publish:ci":"npm publish --provenance --access public","lint:fix:fast":"biome format --write","prepublishOnly":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bf450828-97fb-471f-a7cb-4b0012c7df27"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.7.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^3.24.4","yargs":"^17.7.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.16.1","devDependencies":{"oxlint":"^1.15.0","typescript":"^5.3.0","@types/node":"^20.0.0","@types/yargs":"^17.0.32","@biomejs/biome":"^2.1.2"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_1.0.0_1766177012001_0.06026460348328233","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@socketsecurity/socket-patch","version":"1.2.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@1.2.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"dist/cli.js"},"dist":{"shasum":"aafc104935bd418d03221f6f45a1870795fd03a2","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-1.2.0.tgz","fileCount":181,"integrity":"sha512-VIuDVRRN5V7iyM+OHK4mYrqHPEHbB0J41gPx8iouivvfERwvhPPjDFm+CNjQ1gmYZd1RaqPG3MLT7fKPyMkddA==","signatures":[{"sig":"MEYCIQD342YXyw14htkUqbqCIcOY4WS43R4LRek/CZR7NvhZZQIhAPsYQf3A8Qt1oTBxn94ydzsH8KnPCTN2Wg4QuAl6169q","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":656559},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.js"},"./run":{"types":"./dist/run.d.ts","import":"./dist/run.js","require":"./dist/run.js"},"./hash":{"types":"./dist/hash/git-sha256.d.ts","import":"./dist/hash/git-sha256.js","require":"./dist/hash/git-sha256.js"},"./patch":{"types":"./dist/patch/apply.d.ts","import":"./dist/patch/apply.js","require":"./dist/patch/apply.js"},"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"},"./constants":{"types":"./dist/constants.d.ts","import":"./dist/constants.js","require":"./dist/constants.js"},"./package-json":{"types":"./dist/package-json/index.d.ts","import":"./dist/package-json/index.js","require":"./dist/package-json/index.js"},"./manifest/recovery":{"types":"./dist/manifest/recovery.d.ts","import":"./dist/manifest/recovery.js","require":"./dist/manifest/recovery.js"},"./manifest/operations":{"types":"./dist/manifest/operations.d.ts","import":"./dist/manifest/operations.js","require":"./dist/manifest/operations.js"}},"gitHead":"58c228e042d5878aef9ab659120f73520aa860e2","scripts":{"dev":"tsc --watch","lint":"oxlint -c ./.oxlintrc.json --tsconfig ./tsconfig.json --deny-warnings","test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc","patch":"node dist/cli.js","lint:fix":"pnpm run lint --fix && pnpm run lint:fix:fast","test:unit":"pnpm run build && node --test --test-reporter=spec dist/**/*.test.js","publish:ci":"npm publish --provenance --access public","lint:fix:fast":"biome format --write","prepublishOnly":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bf450828-97fb-471f-a7cb-4b0012c7df27"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.7.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^3.24.4","yargs":"^17.7.2"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.16.1","devDependencies":{"oxlint":"^1.15.0","typescript":"^5.3.0","@types/node":"^20.0.0","@types/yargs":"^17.0.32","@biomejs/biome":"^2.1.2"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_1.2.0_1768065740837_0.24510326380731118","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@socketsecurity/socket-patch","version":"1.6.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@1.6.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"bin/socket-patch"},"dist":{"shasum":"b6bc73c5e2e50477ea2880892711427ce3987888","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-1.6.0.tgz","fileCount":13,"integrity":"sha512-44Ptkk5B2UC7h4P/Df0hOc436WGNwbVlpcvyHPHdJE1XS/dhH3fD7DiFqWeJP+YgnEejH2jqosMIzPpS78rBKw==","signatures":[{"sig":"MEUCIQDhxM/eQ3JoWO0GgHdUUfx+CsYEqFdt0EXuGBga1n3X3gIgajdGoRDaiB1tDkQeYAejrO7NPyrYAGftdrYf+9o2xQ8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@1.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":52362989},"engines":{"node":">=18.0.0"},"gitHead":"2e8e014d53a8b1ad5991effda2033da5d19cd50a","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b95a9eff-acba-4bc8-a6e3-b8a059a7ada8"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.11.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/socket-patch_1.6.0_1772669126626_0.5107554345024916","host":"s3://npm-registry-packages-npm-production"}},"1.6.3":{"name":"@socketsecurity/socket-patch","version":"1.6.3","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@1.6.3","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"bin/socket-patch"},"dist":{"shasum":"f8317835ecc79075788e0c6cd5abe0077c902c62","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-1.6.3.tgz","fileCount":4,"integrity":"sha512-5p1fqFGrL36ZDsU9SGejri5y0nxjNpEXOU4dfBnQHgVBcR6DQiHgTc2lNbMSxA+eujGpUoU1LsAJeMtBE+PZww==","signatures":[{"sig":"MEUCIAKPMFkxSh/xfRymmfa7I9S4B9rFuC4XZX6w/DJHFIgOAiEAsP0NyS5z75UKXFWhpiFnXNr5Km6/1/mp9tgQ1TRrk+w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@1.6.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":16663},"engines":{"node":">=18.0.0"},"gitHead":"d2fc1b881aae33aec23b35e12d08b6e9d7c8beaa","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b95a9eff-acba-4bc8-a6e3-b8a059a7ada8"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.11.0","description":"CLI tool for applying security patches to dependencies","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@socketsecurity/socket-patch-linux-arm":"1.6.3","@socketsecurity/socket-patch-linux-x64":"1.6.3","@socketsecurity/socket-patch-win32-x64":"1.6.3","@socketsecurity/socket-patch-darwin-x64":"1.6.3","@socketsecurity/socket-patch-linux-ia32":"1.6.3","@socketsecurity/socket-patch-win32-ia32":"1.6.3","@socketsecurity/socket-patch-linux-arm64":"1.6.3","@socketsecurity/socket-patch-win32-arm64":"1.6.3","@socketsecurity/socket-patch-darwin-arm64":"1.6.3"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_1.6.3_1772672427973_0.42956207795684254","host":"s3://npm-registry-packages-npm-production"}},"1.7.1":{"name":"@socketsecurity/socket-patch","version":"1.7.1","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@1.7.1","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"bin/socket-patch"},"dist":{"shasum":"d713a799fa577db90cca0dd29cc5658e8d58f9d0","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-1.7.1.tgz","fileCount":7,"integrity":"sha512-fmCYw1lg7+fm5HUIn4rYLpWiLSO0zzted+w0+mblGDJVb+2WY+Hb+r0Xi+6QtBCbIeBFYmcySHEA++uW8vRBpA==","signatures":[{"sig":"MEUCIQCwX7ySav4TkHb9LZkgjr//2x4q7Mc2EOwuH0fPM3W91AIgcUI2IyJ5j/7DTlSHurIg3va3E1yvYFbhG5tMeXF7Dfw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@1.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":22799},"engines":{"node":">=18.0.0"},"exports":{"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"}},"gitHead":"485aa3bfc8645d5b03c31d2915e025f103cf5894","scripts":{"test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b95a9eff-acba-4bc8-a6e3-b8a059a7ada8"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.11.0","description":"CLI tool and schema library for applying security patches to dependencies","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.24.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0"},"optionalDependencies":{"@socketsecurity/socket-patch-linux-arm":"1.7.1","@socketsecurity/socket-patch-linux-x64":"1.7.1","@socketsecurity/socket-patch-win32-x64":"1.7.1","@socketsecurity/socket-patch-darwin-x64":"1.7.1","@socketsecurity/socket-patch-linux-ia32":"1.7.1","@socketsecurity/socket-patch-win32-ia32":"1.7.1","@socketsecurity/socket-patch-linux-arm64":"1.7.1","@socketsecurity/socket-patch-win32-arm64":"1.7.1","@socketsecurity/socket-patch-darwin-arm64":"1.7.1","@socketsecurity/socket-patch-android-arm64":"1.7.1"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_1.7.1_1772810156332_0.1747480560757244","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@socketsecurity/socket-patch","version":"2.0.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@2.0.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"bin/socket-patch"},"dist":{"shasum":"6c7803ef874f102ec1d7fe43a7d5a74c55fe8f06","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-2.0.0.tgz","fileCount":7,"integrity":"sha512-WyKOelgSuE17ReOdcrYQ2fBm6kHvdkDm55b3owHC7WoU1FLNzRnv47J0bkoNgNObB6KedTiQLVzf/ZvbuIl5oQ==","signatures":[{"sig":"MEYCIQCYmJU/ZSLWIr1gMWOqRGI38zw5xDwDhAO22x6LI6o8agIhANidlrRUL8i4TOzn520ctgt6/mrDHxJueGoBT0yzTzv7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":22799},"engines":{"node":">=18.0.0"},"exports":{"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"}},"gitHead":"6127887a4eeecf87035489631a0a620f028256f5","scripts":{"test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b95a9eff-acba-4bc8-a6e3-b8a059a7ada8"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.11.0","description":"CLI tool and schema library for applying security patches to dependencies","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.24.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0"},"optionalDependencies":{"@socketsecurity/socket-patch-linux-arm":"2.0.0","@socketsecurity/socket-patch-linux-x64":"2.0.0","@socketsecurity/socket-patch-win32-x64":"2.0.0","@socketsecurity/socket-patch-darwin-x64":"2.0.0","@socketsecurity/socket-patch-linux-ia32":"2.0.0","@socketsecurity/socket-patch-win32-ia32":"2.0.0","@socketsecurity/socket-patch-linux-arm64":"2.0.0","@socketsecurity/socket-patch-win32-arm64":"2.0.0","@socketsecurity/socket-patch-darwin-arm64":"2.0.0","@socketsecurity/socket-patch-android-arm64":"2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_2.0.0_1772817894127_0.7447185956601394","host":"s3://npm-registry-packages-npm-production"}},"2.1.4":{"name":"@socketsecurity/socket-patch","version":"2.1.4","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@2.1.4","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"bin/socket-patch"},"dist":{"shasum":"6b9ada48b4f336d2d24271aa9a0ddc1dda49fd80","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-2.1.4.tgz","fileCount":7,"integrity":"sha512-zRZ+240ER091j/FY0r5iE6hRoz6wpP+47ogCh8MZFmFGuVjrv9DI/ax4NFeZmPET5ngRCc1MadiVtqqY/gAX9A==","signatures":[{"sig":"MEYCIQCwqEuUm5cenR7o7YOSKoKz2x6DMLWIfR7mU5Bco94HgAIhAJ9gCr9OpoJWbK0Qc5PxoSF7bhdZADeaRlEAL931FRut","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@2.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":24376},"engines":{"node":">=18.0.0"},"exports":{"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"}},"gitHead":"3a581786012bf840ef6d177d9deb7b89133fc898","scripts":{"test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b95a9eff-acba-4bc8-a6e3-b8a059a7ada8"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.12.1","description":"CLI tool and schema library for applying security patches to dependencies","directories":{},"_nodeVersion":"22.22.1","dependencies":{"zod":"^3.24.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0"},"optionalDependencies":{"@socketsecurity/socket-patch-win32-x64":"2.1.4","@socketsecurity/socket-patch-darwin-x64":"2.1.4","@socketsecurity/socket-patch-win32-ia32":"2.1.4","@socketsecurity/socket-patch-win32-arm64":"2.1.4","@socketsecurity/socket-patch-darwin-arm64":"2.1.4","@socketsecurity/socket-patch-android-arm64":"2.1.4","@socketsecurity/socket-patch-linux-arm-gnu":"2.1.4","@socketsecurity/socket-patch-linux-x64-gnu":"2.1.4","@socketsecurity/socket-patch-linux-arm-musl":"2.1.4","@socketsecurity/socket-patch-linux-ia32-gnu":"2.1.4","@socketsecurity/socket-patch-linux-x64-musl":"2.1.4","@socketsecurity/socket-patch-linux-arm64-gnu":"2.1.4","@socketsecurity/socket-patch-linux-ia32-musl":"2.1.4","@socketsecurity/socket-patch-linux-arm64-musl":"2.1.4"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_2.1.4_1775757801735_0.7319354741067616","host":"s3://npm-registry-packages-npm-production"}},"3.3.0":{"name":"@socketsecurity/socket-patch","version":"3.3.0","keywords":["security","patch","cli","dependencies"],"author":{"name":"Socket Security"},"license":"MIT","_id":"@socketsecurity/socket-patch@3.3.0","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"homepage":"https://github.com/SocketDev/socket-patch#readme","bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"bin":{"socket-patch":"bin/socket-patch"},"dist":{"shasum":"7f0cb4fc9ef0ab03e26393c24f16d882cea6477a","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-3.3.0.tgz","fileCount":7,"integrity":"sha512-KH2VMW1jBgUYoVU5TmeEqJDFgBJNTVcAVOMIORClZ8IEAgJ7JVLXq0Bo4Ih8K/0sncvmP9J75X7S5m7xWlbRnQ==","signatures":[{"sig":"MEQCIFSr2RpXZUxfOeKNLkPYuYA39wcFYd55BGxz1C7pZUv2AiAoqrkwdiY2qn06Xo5/370Td0eibVLLUfkHsYdWcdfpjA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@3.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32970},"engines":{"node":">=18.0.0"},"exports":{"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"}},"gitHead":"a74c5c5467d7d36a7aead61046505ddfad2c6321","scripts":{"test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","approver":{"name":"socket-bot","email":"eng@socket.dev"},"trustedPublisher":{"id":"github","oidcConfigId":"oidc:9bd1f491-b1aa-46f8-ac4b-12e072ae5806"}},"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.15.0","description":"CLI tool and schema library for applying security patches to dependencies","directories":{},"_nodeVersion":"22.22.1","dependencies":{"zod":"3.25.76"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.9.3","@types/node":"20.19.41"},"optionalDependencies":{"@socketsecurity/socket-patch-win32-x64":"3.3.0","@socketsecurity/socket-patch-darwin-x64":"3.3.0","@socketsecurity/socket-patch-win32-ia32":"3.3.0","@socketsecurity/socket-patch-win32-arm64":"3.3.0","@socketsecurity/socket-patch-darwin-arm64":"3.3.0","@socketsecurity/socket-patch-android-arm64":"3.3.0","@socketsecurity/socket-patch-linux-arm-gnu":"3.3.0","@socketsecurity/socket-patch-linux-x64-gnu":"3.3.0","@socketsecurity/socket-patch-linux-arm-musl":"3.3.0","@socketsecurity/socket-patch-linux-ia32-gnu":"3.3.0","@socketsecurity/socket-patch-linux-x64-musl":"3.3.0","@socketsecurity/socket-patch-linux-arm64-gnu":"3.3.0","@socketsecurity/socket-patch-linux-ia32-musl":"3.3.0","@socketsecurity/socket-patch-linux-arm64-musl":"3.3.0"},"_npmOperationalInternal":{"tmp":"tmp/socket-patch_3.3.0_1780408359339_0.020727994342545797","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"_id":"@socketsecurity/socket-patch@4.0.0","bin":{"socket-patch":"bin/socket-patch"},"bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"dist":{"shasum":"c15bacf5e7e57f15ff86e3b3e9be12019d786202","tarball":"https://registry.npmjs.org/@socketsecurity/socket-patch/-/socket-patch-4.0.0.tgz","integrity":"sha512-NjuNdoXMaIWIWPP2R6goJzRUyFZwnHz9MIqb2dlPt1WkbxHmJ6muGYeegtsBpgwDO2iqAkGPnaWXV7/0cFpJjA==","fileCount":12,"unpackedSize":118308,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@socketsecurity%2fsocket-patch@4.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBYKF/MDu0njaCfgPr7akQGhs3W4LnN5MZS57LzfAKNnAiEAlDyGCQncc7rpTE7Neecw6HIteDy8CvOevwP1c/kUdA4="}]},"name":"@socketsecurity/socket-patch","author":{"name":"Socket Security"},"engines":{"node":">=18.0.0"},"exports":{"./schema":{"types":"./dist/schema/manifest-schema.d.ts","import":"./dist/schema/manifest-schema.js","require":"./dist/schema/manifest-schema.js"}},"gitHead":"96df6aef12bda08a87d848a42d211013326da7ab","license":"MIT","scripts":{"test":"pnpm run build && node --test dist/**/*.test.js","build":"tsc","prepack":"tsc"},"version":"4.0.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9bd1f491-b1aa-46f8-ac4b-12e072ae5806"},"approver":{"name":"socket-bot","email":"eng@socket.dev"}},"homepage":"https://github.com/SocketDev/socket-patch#readme","keywords":["security","patch","cli","dependencies"],"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"_npmVersion":"11.15.0","description":"CLI tool and schema library for applying security patches to dependencies","directories":{},"maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"_nodeVersion":"22.22.1","dependencies":{"zod":"3.25.76"},"publishConfig":{"access":"public"},"devDependencies":{"typescript":"5.9.3","@types/node":"20.19.41"},"optionalDependencies":{"@socketsecurity/socket-patch-win32-x64":"4.0.0","@socketsecurity/socket-patch-darwin-x64":"4.0.0","@socketsecurity/socket-patch-win32-ia32":"4.0.0","@socketsecurity/socket-patch-win32-arm64":"4.0.0","@socketsecurity/socket-patch-darwin-arm64":"4.0.0","@socketsecurity/socket-patch-android-arm64":"4.0.0","@socketsecurity/socket-patch-linux-arm-gnu":"4.0.0","@socketsecurity/socket-patch-linux-x64-gnu":"4.0.0","@socketsecurity/socket-patch-linux-arm-musl":"4.0.0","@socketsecurity/socket-patch-linux-ia32-gnu":"4.0.0","@socketsecurity/socket-patch-linux-x64-musl":"4.0.0","@socketsecurity/socket-patch-linux-arm64-gnu":"4.0.0","@socketsecurity/socket-patch-linux-ia32-musl":"4.0.0","@socketsecurity/socket-patch-linux-arm64-musl":"4.0.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/socket-patch_4.0.0_1787843724252_0.5489490684424638"},"_hasShrinkwrap":false}},"time":{"created":"2025-11-18T15:59:16.817Z","modified":"2026-08-27T15:15:24.725Z","0.1.0":"2025-11-18T15:59:17.106Z","0.2.0":"2025-12-10T19:36:19.674Z","0.2.1":"2025-12-12T16:35:07.507Z","0.3.0":"2025-12-18T15:17:25.393Z","1.0.0":"2025-12-19T20:43:32.144Z","1.2.0":"2026-01-10T17:22:21.008Z","1.6.0":"2026-03-05T00:05:27.370Z","1.6.3":"2026-03-05T01:00:28.156Z","1.7.1":"2026-03-06T15:15:56.482Z","2.0.0":"2026-03-06T17:24:54.277Z","2.1.4":"2026-04-09T18:03:21.882Z","3.3.0":"2026-06-02T13:52:39.409Z","4.0.0":"2026-08-27T15:15:24.347Z"},"bugs":{"url":"https://github.com/SocketDev/socket-patch/issues"},"author":{"name":"Socket Security"},"license":"MIT","homepage":"https://github.com/SocketDev/socket-patch#readme","keywords":["security","patch","cli","dependencies"],"repository":{"url":"git+https://github.com/SocketDev/socket-patch.git","type":"git"},"description":"CLI tool and schema library for applying security patches to dependencies","maintainers":[{"name":"socket-bot","email":"eng@socket.dev"},{"name":"feross","email":"feross@feross.org"}],"readme":"# Socket Patch CLI\n\nFix known vulnerabilities in the dependencies you already have — without waiting for an\nupstream release, and without a risky version bump.\n\nSocket's security team backports minimal fixes to the *exact versions* of packages you\nhave installed. The `socket-patch` CLI finds which of your dependencies have a patch\navailable and applies it, verifying every changed file by hash. It works across npm,\nPyPI, Cargo, Go, RubyGems, Maven, Composer, NuGet, and Deno, and it can persist the patches\nwhichever way fits your workflow: re-applied by the CLI, committed to your repo, or\npinned in your lockfile. When you're done, it can emit an [OpenVEX\nattestation](#openvex-attestations) so your vulnerability scanner stops flagging the\nCVEs you've already fixed.\n\n**Contents:** [Installation](#installation) · [Five-minute tutorial](#five-minute-tutorial)\n· [How it works](#how-socket-patch-works) · [Common tasks](#common-tasks)\n· [Command reference](#command-reference) · [OpenVEX](#openvex-attestations)\n· [Scripting & CI/CD](#scripting--cicd) · [Manifest format](#manifest-format)\n· [Ecosystem support →](docs/ecosystems.md)\n\n## Installation\n\nOne-line install (macOS / Linux):\n\n```bash\ncurl -fsSL https://install.socket.dev/patch | sh\n```\n\nDetects your platform (macOS/Linux, x64/ARM64), downloads the latest binary, verifies it\nagainst the release's `SHA256SUMS`, and installs to `/usr/local/bin` or `~/.local/bin`.\nUse `sudo sh` instead of `sh` if `/usr/local/bin` requires root. Pin a version with\n`SOCKET_PATCH_VERSION=3.3.0 sh` instead of plain `sh`.\n\nOn a network that blocks or distrusts `github.com`, set `SOCKET_PATCH_BASE_URL` so the\narchives come from Socket too — `install.socket.dev` relays them from the GitHub release,\nchecksums included:\n\n```bash\ncurl -fsSL https://install.socket.dev/patch \\\n  | SOCKET_PATCH_BASE_URL=https://install.socket.dev/patch/SocketDev/socket-patch/releases sh\n```\n\n`install.socket.dev` serves a copy of [`scripts/install.sh`](scripts/install.sh) from\nthis repository — read it before you run it, either there or at\n[install.socket.dev/patch](https://install.socket.dev/patch). If you would rather not\ndepend on the Socket domain, `curl -fsSL\nhttps://raw.githubusercontent.com/SocketDev/socket-patch/main/scripts/install.sh | sh`\ndoes the same thing from the same bytes. See\n[docs/installer-hosting.md](docs/installer-hosting.md) for how the hosted copy is\npublished.\n\nOn Windows, install via npm (below), or grab a prebuilt\n`socket-patch-*-pc-windows-msvc.zip` from the\n[latest release](https://github.com/SocketDev/socket-patch/releases/latest).\n\nOr install through your package manager:\n\n| Package manager | Command |\n|-----------------|---------|\n| npm | `npm install -g @socketsecurity/socket-patch` (or one-shot: `npx @socketsecurity/socket-patch`) |\n| pip | `pip install socket-patch` |\n| cargo | `cargo install socket-patch-cli` (builds from source with every ecosystem compiled in) |\n| gem | `gem install socket-patch` |\n\nThe gem package is a thin launcher: on first run it downloads the prebuilt binary for\nyour platform from the matching GitHub release, verifies its SHA-256, caches it, and\nexecs it. Set `SOCKET_PATCH_BIN` to an existing binary to skip the download.\n\n<details>\n<summary>Manual download</summary>\n\nDownload a prebuilt binary from the [latest release](https://github.com/SocketDev/socket-patch/releases/latest):\n\n```bash\n# macOS (Apple Silicon)\ncurl -fsSL https://github.com/SocketDev/socket-patch/releases/latest/download/socket-patch-aarch64-apple-darwin.tar.gz | tar xz\n\n# macOS (Intel)\ncurl -fsSL https://github.com/SocketDev/socket-patch/releases/latest/download/socket-patch-x86_64-apple-darwin.tar.gz | tar xz\n\n# Linux (x86_64)\ncurl -fsSL https://github.com/SocketDev/socket-patch/releases/latest/download/socket-patch-x86_64-unknown-linux-musl.tar.gz | tar xz\n\n# Linux (ARM64)\ncurl -fsSL https://github.com/SocketDev/socket-patch/releases/latest/download/socket-patch-aarch64-unknown-linux-musl.tar.gz | tar xz\n```\n\nThe musl builds are fully static and run on any distro; glibc (`-gnu`) variants are also\non the releases page, alongside Windows (`socket-patch-x86_64-pc-windows-msvc.zip`) and\nother targets.\n\nThen move the binary onto your `PATH`:\n\n```bash\nsudo mv socket-patch /usr/local/bin/\n```\n\nThe full list of prebuilt targets (Windows, 32-bit ARM, i686, Android) is in\n[docs/ecosystems.md](docs/ecosystems.md#supported-platforms).\n\n</details>\n\n### Updating\n\nIf you installed via the one-liner or a manual download, the CLI updates itself:\n\n```bash\nsocket-patch --update            # latest release (--update 3.4.0 pins a version)\n```\n\nIt downloads the release for your platform, verifies its SHA-256 against the\npublished `SHA256SUMS`, and atomically swaps the binary in place. Package-manager\ninstalls are detected and pointed at their own upgrade command instead (e.g.\n`npm update -g @socketsecurity/socket-patch`). When a newer release exists,\ninteractive runs print a once-a-day reminder on stderr — set\n`SOCKET_NO_UPDATE_CHECK=1` to turn that off.\n\n## Five-minute tutorial\n\nNo account or token is needed to follow along — without an API token `socket-patch`\ntalks to Socket's public patch proxy, which serves the free tier of patches anonymously.\n(An API token unlocks your organization's patch tier; if you've already run\n`socket login` with the separate [Socket CLI](https://docs.socket.dev/docs/socket-cli),\n`socket-patch` picks it up automatically — see\n[Configuration sources](#configuration-sources).)\n\n**1. Scan your project.** From your project root, ask Socket which of your installed\ndependencies have patches available:\n\n```bash\ncd your-project\nsocket-patch scan\n```\n\n`scan` crawls the installed packages it finds (`node_modules/`, virtualenvs, the cargo\nregistry cache, and so on), queries the patch database, prints each available patch with\nits package, severity, and CVE/GHSA identifiers, and asks whether to apply. Say yes and\nthe vulnerable files are rewritten in place — each file is hash-verified before and after\nthe edit.\n\n> If it prints `No patches available for installed packages.`, none of your installed\n> dependency versions currently has a Socket patch — the good outcome, with nothing to\n> apply.\n> To walk the rest of the loop anyway, make a scratch project pinned to a version\n> that has a free patch — at the time of writing, `flatted@3.3.1`:\n>\n> ```bash\n> mkdir demo && cd demo && git init -q && npm init -y && npm install flatted@3.3.1 && socket-patch scan\n> ```\n>\n> (The patch catalog changes over time; if that finds nothing, pick another patched\n> version.)\n\n**2. See what you have.** The applied patches are recorded in `.socket/manifest.json`:\n\n```bash\nsocket-patch list\n```\n\n```\nFound 1 patch(es):\n\nPackage: pkg:npm/flatted@3.3.1\n  UUID: 5cac955f-eab1-4d29-8f4f-c408a6cc9647\n  ...\n  Vulnerabilities (1):\n    - GHSA-25h7-pfq9-p65f (CVE-2026-32141)\n      Severity: HIGH\n```\n\n**3. Make it stick.** Patches applied in place don't survive a reinstall — the next\n`npm install` (or `pip install`, `bundle install`, …) restores the vulnerable upstream\nbytes. Commit the `.socket/` directory and wire an install hook so patches re-apply\nautomatically:\n\n```bash\nsocket-patch setup           # e.g. adds a postinstall script for npm projects\necho '.socket/apply.lock' >> .gitignore   # lock state, not part of the patch record\ngit add .gitignore .socket package.json   # npm example — setup prints which files it changed\ngit commit -m \"apply Socket security patches\"\n```\n\nFrom now on, every install — yours, your teammates', CI's — re-applies the patches. You\ncan also re-apply manually at any time with `socket-patch apply` (it's idempotent).\n\n**4. Undo, if you want.** Remove a patch completely (restores the original files and\ndeletes the manifest entry):\n\n```bash\nsocket-patch remove \"pkg:npm/flatted@3.3.1\"\n```\n\nThat's the whole loop: **scan → apply when prompted → setup → commit**. This tutorial\nused the default *agent* mode, where the CLI re-applies patches after each install.\nThere are two other ways to persist patches — committing the patched packages themselves\n(*vendored*) or pinning them in your lockfile (*hosted*) — and choosing between the\nthree is the next section.\n\n## How Socket Patch works\n\n**A patch** is a minimal fix — usually the upstream security fix, backported — for one\nexact published version of a package. Socket distributes it as per-file edits: for each\ntouched file, the hash of the expected original (`beforeHash`), the hash of the patched\nresult (`afterHash`), and the replacement content. By default, a file whose current\ncontent matches neither the expected original nor the patched result is overwritten with\nthe full verified patched content plus a stderr warning (`content_mismatch_overwritten`);\npass `--strict` (a [global option](#global-options)) to fail closed on mismatch instead,\nor `apply --force` to skip pre-application hash verification entirely (see\n[`apply`](#apply)). Either way the CLI verifies the result after writing. Patches are\nlooked up by package URL ([PURL](https://github.com/package-url/purl-spec)) — e.g.\n`pkg:npm/lodash@4.17.20` — so everything is keyed to exact versions.\n\n**Local state lives in `.socket/`** at your project root, and is designed to be\ncommitted:\n\n| Path | Contents |\n|------|----------|\n| `.socket/manifest.json` | The record of downloaded patches: PURLs, file hashes, vulnerability metadata ([format](#manifest-format)) |\n| `.socket/blobs/` | Patched file contents, named by git-sha256 hash |\n| `.socket/vendor/` | Vendored package artifacts and the vendor/redirect ledgers (only in vendored/hosted modes) |\n\n> Mutating commands also leave a `.socket/apply.lock` file there between runs. It is\n> lock state, not part of the patch record — add it to your `.gitignore`\n> ([`repair`](#repair) deletes it).\n\n### Three patch modes\n\nThe same patched bytes can reach your build three different ways. The modes differ in\n*where the patch lives* and *what must happen at install time*; pick one per project\n(`scan --mode <name>` drives exactly one mode per run).\n\n| Mode | Where the patch lives | Install-time requirement | Trade-off |\n|------|----------------------|--------------------------|-----------|\n| **agent** — `scan --mode agent` (or [`apply`](#apply)) | `.socket/` manifest + blobs, committed; the CLI re-applies after each install | The `socket-patch` CLI must run (install hook via [`setup`](#setup), or an `apply` step in CI) | Small repo footprint (per-file blobs, not whole packages); no lockfile edits; the only mode that needs CI / install-hook changes |\n| **vendored** — `scan --mode vendored` (or [`vendor`](#vendor)) | Patched packages committed under `.socket/vendor/`; the lockfile is rewired to consume them | **None** — the package manager installs the committed bytes | Fully airgapped and hermetic, at the cost of repo size |\n| **hosted** — `scan --mode hosted` | No patched bytes in your repo: the lockfile is rewritten so **only** the patched dependencies resolve to Socket-hosted, integrity-pinned packages on `patch.socket.dev`; the edits + patch records are ledgered in `.socket/vendor/redirect-state.json` (commit it — [`vex`](#vex) reads it, and it records the pre-redirect originals a future revert feature will need; hosted has no CLI revert yet, see [Undo things](#undo-things)) | Installs must be able to reach `patch.socket.dev` (no CLI, no install hook) | Smallest possible diff (lockfile + ledger); not for airgapped installs |\n\nEvery mode pins the patched bytes: in agent mode the CLI verifies every file on each\napply; vendored and hosted modes lean on your package manager's own lockfile integrity\nchecks (sha512 / sha256 / contentHash / CHECKSUMS) where the ecosystem enforces them —\nhosted Maven, which has no lockfile, gets a fail-closed version-suffixing scheme instead.\nA few combinations have weaker install-time pins (vendored Maven, NuGet without a\nlockfile, Go's directory replaces, pipenv's Pipfile.lock) — there the committed bytes\nare the protection; see the [per-ecosystem caveats](docs/ecosystems.md).\n\n**Choosing:** *agent* is the original method and remains fully supported, but it is the\nonly mode that requires CI / install-hook modification — **new projects should prefer\nhosted or vendored**. Pick *vendored* if your builds are airgapped or you don't want an\ninfrastructure dependency; pick *hosted* if you want the smallest diff and your installs\ncan reach `patch.socket.dev`. (Hosted is the planned default for GitHub-app patch PRs —\nit keeps the PR diff small.)\n\nMode support varies by ecosystem — e.g. Go can't do hosted, Rush monorepos can't do\nvendored. See the full **[mode × ecosystem matrix](docs/ecosystems.md#mode--ecosystem-matrix)**\nfor details and per-ecosystem caveats.\n\n## Common tasks\n\n### Patch everything that can be patched\n\n```bash\nsocket-patch scan              # interactive: prompts before applying\nsocket-patch scan --json --mode agent --yes    # non-interactive (CI, scripts)\n```\n\n### Patch one specific CVE, advisory, or package\n\n```bash\nsocket-patch get CVE-2024-12345\nsocket-patch get GHSA-xxxx-yyyy-zzzz\nsocket-patch get lodash                  # fuzzy-matches installed packages\nsocket-patch get \"pkg:npm/lodash@4.17.20\"\n```\n\n`socket-patch <uuid>` with a bare patch UUID is a shortcut for `get <uuid>`.\n\n### Keep patches applied across installs\n\n```bash\nsocket-patch setup             # wire install hooks (npm postinstall, Python .pth, …)\nsocket-patch setup --check     # CI gate: exit non-zero if hooks are missing or a patch drifted\n```\n\nSee [`setup`](#setup) for what gets wired per ecosystem — and which ecosystems (Cargo,\nGo, Maven, NuGet, Deno) have no hook and are patched on demand instead.\n\n### Persist patches with no CI or install-hook changes (vendored / hosted)\n\n```bash\n# Vendored: commit the patched packages themselves (airgap-friendly)\nsocket-patch scan --json --mode vendored --yes\necho '.socket/apply.lock' >> .gitignore\ngit add .gitignore .socket package-lock.json # your lockfile may differ\n\n# Hosted: smallest diff — patched deps resolve from patch.socket.dev\nsocket-patch scan --json --mode hosted --yes\ngit add .socket/vendor/redirect-state.json package-lock.json\n```\n\nNo `setup` hook or CI `apply` step is needed — the package manager installs the patched\nbytes. See [Three patch modes](#three-patch-modes) to choose, and the\n[mode × ecosystem matrix](docs/ecosystems.md#mode--ecosystem-matrix) for what your\necosystem supports.\n\n### Run an auto-update bot in CI\n\nOne command discovers, applies, and garbage-collects in a single pass:\n\n```bash\nsocket-patch scan --json --mode agent --prune --yes\n```\n\nThe working-tree changes (the `.socket/` directory — plus lockfile edits if your bot\nruns `--mode vendored` or `--mode hosted`) are what your PR tooling commits — e.g.\n`peter-evans/create-pull-request` picks them up automatically; use the JSON summary for\nthe PR title/body. See [Scripting & CI/CD](#scripting--cicd), including how to supply\n`SOCKET_API_TOKEN` for org-tier patches.\n\n### Tell your vulnerability scanner about the patches\n\n```bash\nsocket-patch vex --output socket.vex.json\ngrype <image-or-dir> --vex socket.vex.json     # or trivy image --vex ...\n```\n\nThe OpenVEX document marks each patched CVE `not_affected`, so scanners stop flagging\nvulnerabilities you've already remediated. You can also emit it inline from `apply` /\n`scan` / `vendor` with `--vex <path>`. Details in [OpenVEX\nattestations](#openvex-attestations).\n\n### Work offline / airgapped\n\nVendored mode needs no Socket infrastructure and no `socket-patch` binary at install\ntime — the patched packages install from the committed bytes (other, unvendored\ndependencies still resolve from your registry or mirror as usual). Agent mode works\noffline once the blobs are committed:\n\n```bash\nsocket-patch apply --offline   # strict airgap: fails loudly if anything needs the network\n```\n\n`scan` and `get` inherently need the network and refuse to run with `--offline`.\n\n### Undo things\n\nFive commands clean up different layers — the first three undo, the last two reconcile\nand repair; pick by what you want back:\n\n| Command | What it does |\n|---------|--------------|\n| [`rollback`](#rollback) | Restores the original file bytes but **keeps the manifest entry** — the next `apply` re-applies the patch |\n| [`remove`](#remove) | Everything `rollback` does, **plus** it deletes the manifest entry and reverts any vendoring — **permanent**, the patch is fully gone in one command |\n| [`vendor --revert`](#vendor) | **Un-vendors wholesale**: restores the recorded original lockfile fragments byte-for-byte and removes the `.socket/vendor/` artifacts — works without a manifest |\n| [`scan --prune`](#scan) | **Reconciles, doesn't reverse**: drops manifest entries for packages that have left the project and garbage-collects orphan blob/diff/archive files — installed patches stay |\n| [`repair`](#repair) (alias `gc`) | **Restores health, not originals**: re-downloads missing blobs, rebuilds missing/corrupt vendored artifacts, cleans up unused ones, and removes the leftover `apply.lock` file (housekeeping — mutating commands leave it behind after every run) |\n\nAnd `setup --remove` reverts the install hooks that `setup` added.\n\n> Hosted mode has no CLI revert yet: `scan --mode hosted` makes plain lockfile /\n> registry-config edits, so undo them with your version control (e.g.\n> `git checkout -- <lockfile>`) and delete the `.socket/vendor/redirect-state.json`\n> ledger — once you've reverted by hand, its recorded original fragments are stale, and\n> a leftover ledger would still let [`vex`](#vex) attest the removed redirects.\n\n## Command reference\n\n| Command | What it does |\n|---------|--------------|\n| [`scan`](#scan) | Scan installed packages for available security patches |\n| [`apply`](#apply) | Apply security patches from the local manifest |\n| [`vex`](#vex) | Generate an OpenVEX attestation for the applied patches |\n| [`vendor`](#vendor) | Eject patched dependencies into committable `.socket/vendor/` |\n| [`setup`](#setup) | Wire install hooks so patches re-apply automatically |\n| [`rollback`](#rollback) | Restore original files (keeps the manifest) |\n| [`get`](#get) | Fetch and apply a patch by UUID / CVE / GHSA / PURL / name (alias: `download`) |\n| [`list`](#list) | List all patches in the local manifest |\n| [`remove`](#remove) | Remove a patch: roll back files + delete the manifest entry |\n| [`repair`](#repair) | Download missing blobs, clean up unused ones, tidy lock state (alias: `gc`) |\n\n### Global options\n\nThese flags are accepted by **every** subcommand and go after the command name —\n`socket-patch <command> --json --cwd ./app` works uniformly (`socket-patch --json\n<command>` is a parse error). A command silently ignores any global flag it doesn't use\n(e.g. `list --global` parses fine and the flag is a no-op).\n\nEach flag has a matching `SOCKET_*` environment variable, listed in the table;\ncommand-specific flags list theirs in each command's own table. **Precedence is CLI arg\n> env var > default** — with one extra fallback layer for the three authentication\nsettings, described in [Configuration sources](#configuration-sources) below.\n\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--cwd <dir>` | `SOCKET_CWD` | Working directory (default: `.`). The manifest path is resolved relative to this. |\n| `--manifest-path <path>` | `SOCKET_MANIFEST_PATH` | Path to the patch manifest, resolved relative to `--cwd` (default: `.socket/manifest.json`). |\n| `--api-url <url>` | `SOCKET_API_URL` | Socket API URL for the authenticated endpoint (default: `https://api.socket.dev`). |\n| `--api-token <token>` | `SOCKET_API_TOKEN` | Socket API token — optional. When no token resolves from any source, the anonymous public patch proxy is used (free patches). See [Configuration sources](#configuration-sources) for how to obtain and persist one. |\n| `-o, --org <slug>` | `SOCKET_ORG_SLUG` | Organization slug. Auto-resolved when omitted and a token is set. |\n| `--proxy-url <url>` | `SOCKET_PROXY_URL` | Public proxy URL used when no API token is set (default: `https://patches-api.socket.dev`). |\n| `-e, --ecosystems <list>` | `SOCKET_ECOSYSTEMS` | Restrict to specific ecosystems (comma-separated, e.g. `npm,pypi`). Unknown names are rejected. |\n| `--download-mode <mode>` | `SOCKET_DOWNLOAD_MODE` | Artifact to fetch when local files are missing: `diff` (default, smallest delta) or `file` (legacy per-file blobs). |\n| `--vendor-source <mode>` | `SOCKET_VENDOR_SOURCE` | How `vendor` acquires the installable artifact: `auto` (default — download the prebuilt package from patch.socket.dev, fall back to a local build on any miss), `service` (require the service, fail-closed), or `build` (always build locally). Covers npm, pypi, cargo, golang, composer, gem, nuget, and maven. |\n| `--vendor-url <url>` | `SOCKET_VENDOR_URL` | Base host for the vendoring service's package-reference request (default: the active `--api-url`/`--proxy-url` base). Point at staging / local dev for testing. |\n| `--patch-server-url <url>` | `SOCKET_PATCH_SERVER_URL` | Override the host of the prebuilt-archive download URL the service returns (default: as returned). Mainly for local-dev / testing. |\n| `--offline` | `SOCKET_OFFLINE` | Strict airgap: never contact the network. Operations that need remote data fail loudly. |\n| `--strict` | `SOCKET_STRICT` | Fail-closed on before-hash mismatches instead of the default warn-and-overwrite: a file whose current content matches neither `beforeHash` nor `afterHash` aborts that package's apply. Overridden by `--force`. |\n| `-g, --global` | `SOCKET_GLOBAL` | Operate on globally-installed packages. |\n| `--global-prefix <path>` | `SOCKET_GLOBAL_PREFIX` | Override the path used to discover globally-installed packages. |\n| `-j, --json` | `SOCKET_JSON` | Emit machine-readable JSON output. Every JSON response includes a `\"status\"` field — camelCase on the envelope commands (`\"success\"`, `\"error\"`, `\"noManifest\"`, `\"partialFailure\"`, `\"paidRequired\"`, `\"notFound\"`; apply/list/repair/remove/vendor), snake_case on the legacy shapes (`\"partial_failure\"`, `\"not_found\"`; get/scan/rollback/setup). See [CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md) for the exact shapes. |\n| `-v, --verbose` | `SOCKET_VERBOSE` | Show extra detail in human-readable output. |\n| `-s, --silent` | `SOCKET_SILENT` | Suppress non-error output. |\n| `--dry-run` | `SOCKET_DRY_RUN` | Preview the operation without making any mutations. |\n| `-y, --yes` | `SOCKET_YES` | Skip interactive confirmation prompts. |\n| `--lock-timeout <secs>` | `SOCKET_LOCK_TIMEOUT` | Seconds to wait for `.socket/apply.lock` before giving up. `0`/unset = a single non-blocking try; a positive value retries with backoff. Only meaningful for mutating commands (`apply`, `rollback`, `repair`, `remove`). |\n| `--debug` | `SOCKET_DEBUG` | Emit verbose debug logs to stderr. |\n| `--no-telemetry` | `SOCKET_TELEMETRY_DISABLED` | Disable anonymous usage telemetry. |\n\n#### Configuration sources\n\nFor the three authentication settings, the [Socket CLI](https://docs.socket.dev/docs/socket-cli)'s\npersisted login sits between the env var and the built-in default — run `socket login`\n(or `socket config set apiToken` / `defaultOrg`) once and `socket-patch` picks it up\ntoo. The `SOCKET_CLI_*` env vars the JS CLI reads are honored as peer aliases as well,\nso one export configures both tools. To set a token directly instead, create one in the\n[Socket dashboard](https://socket.dev) under your organization's API tokens settings and\nuse the raw token (`sktsec_<...>_api`) shown at generation time, **not** the\n`sha512-...` display hash. Resolution is per key, and an empty value means \"unset\" at\nevery layer:\n\n```\n--api-token / --org / --api-url\n  1. CLI flag\n  2. Env var           SOCKET_API_TOKEN / SOCKET_ORG_SLUG / SOCKET_API_URL — or the\n                       SOCKET_CLI_* peer aliases (SOCKET_CLI_API_TOKEN /\n                       SOCKET_CLI_ORG_SLUG / SOCKET_CLI_API_BASE_URL); the\n                       canonical name wins when both are set\n  3. socket-cli config <data dir>/socket/settings/config.json — read-only\n                       (Linux: $XDG_DATA_HOME, else ~/.local/share;\n                        macOS: $XDG_DATA_HOME, else ~/Library/Application Support,\n                        then legacy ~/.local/share; Windows: %LOCALAPPDATA%)\n  4. Built-in default  no token → public proxy; org → auto-resolve;\n                       url → https://api.socket.dev\n```\n\nTwo env-only toggles adjust this. `SOCKET_NO_API_TOKEN=1` ignores ambient tokens (env +\nconfig; an explicit `--api-token` still wins) — useful to force the anonymous public\nproxy in CI or a test run. `SOCKET_NO_CONFIG=1` disables the config-file layer entirely.\n`socket-patch` never *writes* the config file, and a corrupt one only produces a stderr\nwarning — it never breaks a command or pollutes `--json` output. `socket-patch` does\n**not** read `.env` files or any per-repository config for endpoints or credentials: a\ncloned repo must never be able to redirect where patches come from or spend your token.\n(Full rationale: [docs/design/configuration.md](docs/design/configuration.md).)\n\nThe sections below list only each command's **command-specific** flags.\n\n### `scan`\n\nScan installed packages for available security patches — and, with `--mode`, act on what\nit finds. `scan` is the entry point for all three [patch modes](#three-patch-modes):\n\n- `--mode agent` downloads and applies the selected patches in place;\n- `--mode vendored` discovers, downloads, and builds + wires the committable\n  `.socket/vendor/` artifacts in one pass (re-vendoring automatically when a newer patch\n  is selected);\n- `--mode hosted` rewrites lockfiles / registry configs so only the patched dependencies\n  resolve to Socket-hosted packages.\n\nWithout a mode, interactive `scan` prompts before applying, and `scan --json` is\nread-only (discovery plus an `updates[]` array; no mutation).\n\n`scan --mode agent --prune` is the single command bots need for full auto-update: it\ndiscovers patches, applies them, and garbage-collects orphan blob files plus manifest\nentries for uninstalled packages — all in one invocation.\n\n**Usage:**\n```bash\nsocket-patch scan [options]\n```\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--mode <hosted\\|vendored\\|agent>` | — | Selects one of the three [patch modes](#three-patch-modes), summarized above. Combining `--mode` with a legacy boolean flag of a *different* mode is an error (exit 2); the same mode spelled both ways is accepted. |\n| `--prune` | — | Garbage-collect after the scan: remove manifest entries for packages no longer present in the crawl (installed trees + lockfiles — a wiped `node_modules` alone doesn't prune lockfile-listed entries) and delete orphan blob/diff/package-archive files. Off by default. [Vendored](#vendor) packages are exempt from the crawl-based prune (an absent installed copy is their normal state), but a vendored entry whose dependency has left the lockfile is reverted and its manifest entry dropped. Orthogonal to `--mode` — combines with any mode. |\n| `--detached` | — | With `--mode vendored`: skip all `.socket/manifest.json` writes — the vendor ledger embeds the patch records instead. For projects that want the vendored patches *only* in the lockfile + `.socket/vendor/`. Detached patches are invisible to `apply`/`rollback`/`repair`; undo them with `remove <purl>` or `vendor --revert`. |\n| `--batch-size <n>` | `SOCKET_BATCH_SIZE` | Packages per API request (default: `100`). |\n| `--all-releases` | `SOCKET_ALL_RELEASES` | Store patches for every release/distribution variant, not just the installed one — PyPI wheel/sdist, RubyGems platform, Maven classifier. Makes the manifest portable across environments (e.g. cross-platform CI caches). |\n| `--vex <path>` | `SOCKET_VEX` | On a successful scan, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX generation](#inline-vex-on-apply--scan--vendor). |\n| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. |\n\n> Deprecated boolean spellings of `--mode` remain supported for back-compat: `--apply`\n> (== `--mode agent`) and `--vendor` (== `--mode vendored`); prefer `--mode`. `--sync`\n> is not deprecated — it is convenience sugar for `--mode agent` + `--prune`, the\n> single-flag bot invocation (`scan --json --sync --yes`).\n\n> Use `--dry-run` to preview what any moded run (with or without `--prune`) would do\n> without mutating disk.\n\n**Examples:**\n```bash\n# Scan local project (interactive prompt to apply)\nsocket-patch scan\n\n# Scan with JSON output (discover + updates, no mutation)\nsocket-patch scan --json\n\n# Agent mode: discover + apply patches in place (non-interactive)\nsocket-patch scan --json --mode agent --yes\n\n# Auto-update bot: discover, apply, garbage-collect — all in one\nsocket-patch scan --json --mode agent --prune --yes\n\n# Preview an agent-mode + prune run without mutating disk\nsocket-patch scan --json --mode agent --prune --yes --dry-run\n\n# Scan only npm packages\nsocket-patch scan --ecosystems npm\n\n# Scan global packages\nsocket-patch scan -g\n\n# Agent mode + emit an OpenVEX attestation in one pass\nsocket-patch scan --json --mode agent --prune --yes --vex socket.vex.json\n\n# Vendored mode: build + commit every patched dependency (see the vendor\n# command). Works on a completely fresh clone: dependencies listed in the\n# lockfile but not yet installed are fetched pristine from their registry and\n# integrity-verified against the lockfile before vendoring.\nsocket-patch scan --json --mode vendored --yes\n\n# Same, but keep the manifest out of it entirely\nsocket-patch scan --json --mode vendored --detached --yes\n\n# Preview a vendored run (would_vendor / would_revendor / already_vendored)\nsocket-patch scan --json --mode vendored --yes --dry-run\n\n# Hosted mode: rewrite lockfiles so patched deps resolve to Socket-hosted\n# integrity-pinned packages — no artifact bytes in the repo, no CI changes.\nsocket-patch scan --json --mode hosted --yes\n```\n\n> Already-vendored packages are **skipped by plain `--mode agent`** (the committed\n> artifact is the patch); a newer available patch still appears in the JSON `updates[]`\n> array — re-run `scan --mode vendored` to take it.\n>\n> Hosted-managed dependencies get the same signal: `updates[]` also consults the\n> `.socket/vendor/redirect-state.json` ledger, so a superseded hosted patch shows up in\n> read-only `scan --json` — re-run `scan --mode hosted` to take it.\n\n### `apply`\n\nApply security patches from the local manifest. Idempotent — safe to run from install\nhooks and CI on every build.\n\n**Usage:**\n```bash\nsocket-patch apply [options]\n```\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `-f, --force` | `SOCKET_FORCE` | Skip pre-application hash verification (apply even if package version differs). |\n| `--check` | — | Read-only audit that the committed **Go** `replace`-redirects match the manifest (for CI / GitHub-App auditing) — Go only, since cargo patches in place and has no redirect to audit. Lock-free, crawl-free, and offline-safe: exits 0 in sync, 1 on drift. Vendored modules are excluded from the audit. |\n| `--vex <path>` | `SOCKET_VEX` | On a successful apply, also write an OpenVEX 0.2.0 document to this path. See [Inline VEX generation](#inline-vex-on-apply--scan--vendor). |\n| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder; mirror the standalone [`vex`](#vex) knobs. Inert unless `--vex` is set. |\n\n**Examples:**\n```bash\n# Apply patches\nsocket-patch apply\n\n# Dry run\nsocket-patch apply --dry-run\n\n# Apply only npm patches\nsocket-patch apply --ecosystems npm\n\n# Apply in offline mode\nsocket-patch apply --offline\n\n# JSON output for CI/CD\nsocket-patch apply --json\n\n# Apply and emit an OpenVEX attestation in one step\nsocket-patch apply --vex socket.vex.json\n```\n\n> Packages managed by [`vendor`](#vendor) are skipped (`skipped`/`vendored` in JSON): the\n> committed vendored artifact is the patch, so there is nothing for `apply` to do — even\n> when the installed tree (e.g. `node_modules/`) is absent.\n\n### `vex`\n\nGenerate an [OpenVEX](https://github.com/openvex) 0.2.0 attestation describing the\nvulnerabilities that the applied patches have mitigated. See [OpenVEX\nattestations](#openvex-attestations) below for the full workflow.\n\n**Usage:**\n```bash\nsocket-patch vex [options]\n```\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `-O, --output <path>` | `SOCKET_VEX_OUTPUT` | Write the VEX document to this path instead of stdout. Required when combined with `--json`. |\n| `--product <id>` | `SOCKET_VEX_PRODUCT` | Override the auto-detected top-level product PURL/identifier. |\n| `--no-verify` | `SOCKET_VEX_NO_VERIFY` | Skip the on-disk file-hash check and trust the manifest — useful on a build machine that doesn't have the patched files laid out. |\n| `--doc-id <id>` | `SOCKET_VEX_DOC_ID` | Override the document `@id`. Default is a random `urn:uuid:<v4>` regenerated each run; pin this for a reproducible identifier. |\n| `--compact` | `SOCKET_VEX_COMPACT` | Emit compact JSON instead of pretty-printed. |\n\n**Examples:**\n```bash\n# Print a VEX document to stdout (human-readable status goes to stderr)\nsocket-patch vex\n\n# Write the document to a file\nsocket-patch vex --output socket.vex.json\n\n# CI shape: VEX doc to file, machine-readable envelope to stdout\nsocket-patch vex --json --output socket.vex.json\n\n# Generate on a build box without verifying on-disk files\nsocket-patch vex --no-verify --output socket.vex.json\n```\n\n### `vendor`\n\n`apply`'s **committable** sibling — the standalone command behind\n[vendored mode](#three-patch-modes) (`scan --mode vendored` runs discovery + this engine\nin one pass). Instead of patching installed packages in place (machine-local state),\n`vendor` ejects each patched package into `.socket/vendor/<ecosystem>/<patch-uuid>/…` and\nrewires your lockfile so the project consumes the vendored copy. Commit `.socket/` — the\nvendored artifacts plus the manifest that [`vex`](#vex), [`list`](#list), and\n[`repair`](#repair) read — along with the lockfile edits, and **every fresh checkout\nbuilds with the patched dependency**: no `socket-patch` binary, no Socket API access, no\ninstall hook required on the consuming machine.\n\nVendoring is per-patch: only dependencies with a Socket patch are vendored. For the\nlockfile flavors each ecosystem supports, see the\n[mode × ecosystem matrix](docs/ecosystems.md#mode--ecosystem-matrix).\n\n**Usage:**\n```bash\nsocket-patch vendor [options]\n```\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `-f, --force` | `SOCKET_FORCE` | Tolerate *missing* patch-target files in the staged copy (skipped instead of failing the vendor) and bypass the variant probe for multi-release ecosystems. A plain before-hash mismatch doesn't need this: vendor staging always overwrites mismatched content with the verified patched bytes (surfaced as a `vendor_content_mismatch_overwritten` warning). |\n| `--revert` | `SOCKET_VENDOR_REVERT` | Undo vendoring: restore the recorded original lockfile fragments byte-for-byte and remove the `.socket/vendor/` artifacts. Works without a manifest. |\n| `--vex <path>` | `SOCKET_VEX` | On a successful vendor, also write an OpenVEX 0.2.0 document to this path. |\n| `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, `--vex-compact` | `SOCKET_VEX_*` | Passthrough to the embedded VEX builder. Inert unless `--vex` is set. |\n\n**How it interacts with the rest of the CLI** — once a package is vendored, `vendor` owns\nit:\n\n- [`apply`](#apply) and [`rollback`](#rollback) skip vendored packages (they never touch\n  a vendor-owned tree or lockfile entry).\n- [`remove`](#remove) **reverts the vendoring** as part of removing the patch — lockfile\n  restored, artifact deleted — so one command fully undoes it.\n- [`scan`](#scan) skips downloading/applying patches for vendored packages, and\n  `--prune` exempts them from its crawl-based prune (though a vendored entry whose\n  dependency has left the lockfile is reverted and dropped); newer patches show up in\n  `updates[]` as the signal to re-run `scan --mode vendored`.\n- [`vex`](#vex) attests vendored patches by verifying the **committed artifact** (marked\n  `(vendored)` in the impact statement) — no `setup` install hook needed.\n- Re-running `vendor` is idempotent; patches dropped from the manifest are auto-reverted\n  on the next run.\n\n**Examples:**\n```bash\n# Vendor every patched dependency listed in the manifest\nsocket-patch vendor\n\n# Preview without writing anything\nsocket-patch vendor --dry-run\n\n# Then make it stick: commit .socket/ (vendor artifacts + manifest) and the lockfile\n# (gitignore .socket/apply.lock — see \"How Socket Patch works\")\ngit add .socket package-lock.json && git commit -m \"vendor Socket patches\"\n\n# Undo everything (restores the original lockfile byte-for-byte)\nsocket-patch vendor --revert\n\n# JSON output for scripting\nsocket-patch vendor --json\n```\n\n> Prefer one command? [`scan --mode vendored`](#scan) discovers, downloads, *and* vendors\n> in a single pass.\n\n### `setup`\n\nConfigure your project so patches are **re-applied automatically after install** — no\nmanual `socket-patch apply` step in CI. `setup` is a one-time operation: run it, commit\nthe change together with your `.socket/` patches, and every later install handles the\nrest. It is strictly **opt-in** — nothing is hooked unless you run `setup` and commit the\nresult.\n\nWhat gets wired, per ecosystem:\n\n- **npm / yarn / pnpm / bun** — writes `postinstall` and `dependencies` scripts into\n  `package.json` so any install — including `npm install <pkg>` — re-applies patches\n  (pnpm: root package only).\n- **Python (pip / uv / poetry / pdm / hatch)** — Python has no universal post-install\n  hook, so `setup` instead adds a **`socket-patch[hook]`** dependency to your manifest\n  (`pyproject.toml` / `requirements.txt`; for classic Poetry, the equivalent\n  `socket-patch = { extras = [\"hook\"] }`). Installing it lays down\n  a startup `.pth` (shipped by the small `socket-patch-hook` wheel) that re-applies your\n  committed `.socket/` patches the next time the interpreter runs. It is\n  package-manager-agnostic (it rides the interpreter, not any one installer) and\n  **fail-open** — a hook error can never break interpreter startup. Details below.\n- **RubyGems (Bundler)** — adds a managed `plugin \"socket-patch\"` block to the `Gemfile`\n  and generates an in-tree Bundler plugin under `.socket/bundler-plugin/`. It re-applies\n  patches on every `bundle install` (cached *and* fresh). (Requires the `socket-patch`\n  CLI on `PATH`, and **bundler >= 2.2**: bundler 1.x cannot load a `plugin ... path:`\n  directive — it resolves it as an ordinary gem and every later `bundle install` fails —\n  so `setup` refuses to wire a project whose lock or `bundle --version` reports an older\n  bundler, and `setup --check` red-flags a wired project that lands in that state.)\n- **Composer (PHP)** — appends `socket-patch apply` to `composer.json`'s\n  `post-install-cmd` / `post-update-cmd` script events, so patches re-apply on every\n  `composer install` / `composer update`. (Requires the `socket-patch` CLI on `PATH`.)\n- **Cargo & Go** — *apply-only, no `setup` hook.* A one-click auto-repatch-on-build isn't\n  possible for these, so `setup` skips them. Patch with `socket-patch apply` directly:\n  **cargo** patches the crate in place (in `vendor/` or the registry cache, rewriting\n  `.cargo-checksum.json` so `cargo build` accepts it) — note that a non-vendored crate\n  patches the **shared** `$CARGO_HOME/registry` cache, which affects every project on\n  the machine and is silently reset by `cargo clean` or a cache prune; vendor the\n  dependency (`--mode vendored`) for a project-local, committable patch. **go** writes a\n  project-local patched copy under `.socket/go-patches/` plus a `go.mod` `replace`\n  directive (the module cache is `go.sum`-verified, so in-place patching can't build);\n  commit `go.mod` + `.socket/go-patches/` so a clone builds the patched bytes. To have\n  [`vex`](#vex) still attest these hand-applied patches, add a `setup.manual` array to\n  `.socket/manifest.json` by hand (there is no CLI flag for it yet):\n  `\"setup\": { \"manual\": [\"cargo\", \"golang\"] }`.\n- **Maven / NuGet / Deno** — also apply-only: no native install hook exists to wire, so\n  `setup` reports `no_files`; patch them on demand with `socket-patch apply`, and declare\n  them in `setup.manual` (the same hand-edit as the Cargo & Go note above, e.g.\n  `\"setup\": { \"manual\": [\"deno\"] }`) so [`vex`](#vex) still attests the hand-applied\n  patches — this matters most for Deno, which has no vendored or hosted alternative.\n  For Maven\n  and NuGet, note that in-place patching leaves the caches' own checksum sidecars stale\n  (NuGet's fixup deletes `.nupkg.metadata` and raises an advisory for the signed-package\n  `.nupkg.sha512` marker; Maven's `.jar.sha1`/`.jar.md5` are left as-is) — the copy-out\n  modes, `scan --mode vendored` and `scan --mode hosted`, never touch the caches and\n  avoid the issue entirely. See\n  [ecosystems.md](docs/ecosystems.md#maven--nuget-caveats).\n\n**Usage:**\n```bash\nsocket-patch setup            # configure (interactive)\nsocket-patch setup --check    # verify configured; non-zero exit if not (CI gate)\nsocket-patch setup --remove   # revert what setup added\n```\n\n**Command-specific options** (plus all [Global options](#global-options) — `--dry-run`,\n`--yes`, `--json`, `--cwd` are the most relevant):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--check` | — | Read-only verification that every manifest is configured **and** every installed patch is still applied on disk (each file matches its recorded `afterHash`); exits non-zero if any manifest still needs setup or a patch has drifted. Never writes (safe in CI). Conflicts with `--remove`. |\n| `--remove` | — | Revert every install hook `setup` added (npm `package.json` scripts, the Python `socket-patch[hook]` dependency, the gem Bundler plugin wiring — including bundler's machine-local `.bundle/plugin` registration, so later `bundle install`s don't warn about the unwired plugin — and the Composer `post-install-cmd`/`post-update-cmd` script entries). If the registration can't be cleared automatically (unexpected index format), the error names the fallback: `bundler plugin uninstall socket-patch`. |\n| `--exclude <paths>` | `SOCKET_SETUP_EXCLUDE` | Workspace-member path(s) to exclude from setup (comma-separated, relative to the repo root). The exclusion is persisted in `.socket/manifest.json`, so `setup --check` and a fresh clone honor it without re-passing the flag. |\n\n#### Disabling / opting out (Python hook)\n\nThe Python hook is designed to be easy to skip or remove:\n\n- **Per interpreter / CI step:** set `SOCKET_PATCH_HOOK=off` (or `SOCKET_NO_HOOK=1`).\n  This is checked *before any hook code runs*, so it fully bypasses the hook for that\n  process.\n- **Remove from a project:** `socket-patch setup --remove`, then\n  `pip uninstall socket-patch-hook`.\n- **Never opted in:** if you don't run `setup`, there is no hook — it is opt-in by\n  design.\n\n#### What the Python hook does, and its safety model\n\nOn interpreter startup, *only when the set of installed packages changed*, the hook runs\n`socket-patch apply --offline --ecosystems pypi` for the project that owns the current\nvirtualenv, re-applying only the patches committed in that project's `.socket/`.\nSpecifically:\n\n- It is **anchored to the virtualenv** it is installed in (not the working directory), so\n  a `python` started from an unrelated directory cannot pull in a foreign\n  `.socket/manifest.json`.\n- It **verifies each file's hash before patching** and **never writes outside the\n  installed package directory** (path-escaping manifest keys are refused).\n- It **prefers the binary shipped in the installed `socket-patch` package** over `PATH`,\n  so a binary planted earlier on `PATH` cannot shadow it; `PATH` is consulted only as a\n  fallback when that package isn't installed.\n- It runs **offline** (no network at startup) and is **fail-open** (any error is\n  swallowed; it can never abort the interpreter).\n\n**Examples:**\n```bash\n# Interactive setup (all detected ecosystems, auto-detected)\nsocket-patch setup\n\n# Non-interactive\nsocket-patch setup -y\n\n# Preview changes\nsocket-patch setup --dry-run\n\n# Verify configuration in CI (exits non-zero if not set up or a patch has drifted)\nsocket-patch setup --check\n\n# JSON output for scripting\nsocket-patch setup --json -y\n```\n\n### `rollback`\n\nRoll back patches to restore the original files. If no identifier is given, all patches\nare rolled back. The manifest entries are kept, so a later `apply` re-applies the patches\n— use [`remove`](#remove) to delete a patch permanently.\n\nPackages managed by [`vendor`](#vendor) are excluded — their patch lives in the committed\nartifact, not the installed tree — and are listed in the JSON output's `vendored` array\n(use `remove` or `vendor --revert` to undo them).\n\n**Usage:**\n```bash\nsocket-patch rollback [identifier] [options]\n```\n\n**Arguments:**\n- `identifier` — package PURL or patch UUID to roll back. Omit to roll back all patches.\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--one-off` | `SOCKET_ONE_OFF` | Reserved: rollback by fetching original (`beforeHash`) files from the API, no manifest required. **Not yet implemented** — the command currently errors up front. |\n\n**Examples:**\n```bash\n# Rollback all patches\nsocket-patch rollback\n\n# Rollback a specific package\nsocket-patch rollback \"pkg:npm/lodash@4.17.20\"\n\n# Rollback by UUID\nsocket-patch rollback 550e8400-e29b-41d4-a716-446655440000\n\n# Dry run\nsocket-patch rollback --dry-run\n\n# JSON output\nsocket-patch rollback --json\n```\n\n### `get`\n\nGet a security patch from the Socket API and apply it. Accepts a UUID, CVE ID, GHSA ID,\nPURL, or package name. The identifier type is auto-detected but can be forced with a\nflag.\n\nAlias: `download`. And as a shortcut, `socket-patch <uuid>` with a bare patch UUID is\nrewritten to `socket-patch get <uuid>`.\n\n**Usage:**\n```bash\nsocket-patch get <identifier> [options]\n```\n\n**Arguments:**\n- `identifier` — patch UUID, CVE ID, GHSA ID, package PURL, or package name. Type is\n  auto-detected; force it with `--id` / `--cve` / `--ghsa` / `--package`.\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--id` | — | Force identifier to be treated as a UUID. |\n| `--cve` | — | Force identifier to be treated as a CVE ID. |\n| `--ghsa` | — | Force identifier to be treated as a GHSA ID. |\n| `-p, --package` | — | Force identifier to be treated as a package name. |\n| `--save-only` | `SOCKET_SAVE_ONLY` | Download the patch without applying it (alias: `--no-apply`). |\n| `--one-off` | `SOCKET_ONE_OFF` | Reserved: apply the patch immediately without saving to the `.socket` folder. **Not yet implemented** — the command currently errors up front. |\n| `--all-releases` | `SOCKET_ALL_RELEASES` | Download patches for every release/distribution variant of a matched package (PyPI wheel/sdist, RubyGems platform, Maven classifier), not just the installed one. |\n\n> Authenticated lookups run against an org. The slug is auto-resolved from your token\n> when omitted; pass `--org <slug>` (or set `SOCKET_ORG_SLUG`) to pick one explicitly —\n> useful when the token belongs to multiple orgs.\n\n**Examples:**\n```bash\n# Get patch by UUID\nsocket-patch get 550e8400-e29b-41d4-a716-446655440000\n\n# Get patch by CVE\nsocket-patch get CVE-2024-12345\n\n# Get patch by GHSA\nsocket-patch get GHSA-xxxx-yyyy-zzzz\n\n# Get patch by package name (fuzzy matches installed packages)\nsocket-patch get lodash\n\n# Download only, don't apply\nsocket-patch get CVE-2024-12345 --save-only\n\n# Apply to global packages\nsocket-patch get lodash -g\n\n# JSON output for scripting\nsocket-patch get CVE-2024-12345 --json -y\n```\n\n### `list`\n\nList all patches in the local manifest.\n\n**Usage:**\n```bash\nsocket-patch list [options]\n```\n\nNo command-specific options — see [Global options](#global-options) (`--json`,\n`--manifest-path`, `--cwd` are the relevant ones).\n\n**Examples:**\n```bash\n# List patches\nsocket-patch list\n\n# JSON output\nsocket-patch list --json\n```\n\n**Sample output:**\n```\nFound 1 patch(es):\n\nPackage: pkg:npm/flatted@3.3.1\n  UUID: 5cac955f-eab1-4d29-8f4f-c408a6cc9647\n  Tier: free\n  License: MIT\n  Exported: Wed, 18 Mar 2026 22:53:26 GMT\n  Vulnerabilities (1):\n    - GHSA-25h7-pfq9-p65f (CVE-2026-32141)\n      Severity: HIGH\n      Summary: flatted vulnerable to unbounded recursion DoS in parse() revive phase\n  Files patched (6):\n    - package/cjs/index.js\n    - package/es.js\n    ...\n```\n\n### `remove`\n\nRemove a patch from the manifest (rolls back files first by default). If the package is\n[vendored](#vendor), `remove` also **reverts the vendoring** — the lockfile is restored\nbyte-for-byte and the `.socket/vendor/` artifact is deleted — so the patch is fully gone\nin one command. Detached-vendored patches (from `scan --mode vendored --detached`) are\nremovable by PURL or UUID too, even though they have no manifest entry.\n\n**Usage:**\n```bash\nsocket-patch remove <identifier> [options]\n```\n\n**Arguments:**\n- `identifier` — package PURL (e.g. `pkg:npm/package@version`) or patch UUID.\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--skip-rollback` | `SOCKET_SKIP_ROLLBACK` | Only update the manifest, do not restore original files (for vendored packages this also leaves the vendor wiring + artifact in place). |\n\n**Examples:**\n```bash\n# Remove by PURL\nsocket-patch remove \"pkg:npm/lodash@4.17.20\"\n\n# Remove by UUID\nsocket-patch remove 550e8400-e29b-41d4-a716-446655440000\n\n# Remove without rolling back files\nsocket-patch remove \"pkg:npm/lodash@4.17.20\" --skip-rollback\n\n# JSON output\nsocket-patch remove \"pkg:npm/lodash@4.17.20\" --json\n```\n\n### `repair`\n\nDownload missing blobs, clean up unused blobs, and reset the advisory lock state.\n\nAlias: `gc`\n\n`repair` cleans up the `.socket/` directory without running a scan — useful when you've\nmanually adjusted the manifest, recovered from a partial-failure state, or just want to\nfree space. It also rebuilds missing or corrupt vendored artifacts. For the combined\nworkflow (discover + apply + GC in one pass), use\n`scan --json --mode agent --prune --yes` instead.\n\nAs its final step, `repair` removes the leftover `.socket/apply.lock` file that mutating\ncommands retain between runs (skipped under `--dry-run`). A leftover file from a crashed\nrun never blocks anything — the OS releases a dead process's lock automatically — so this\nis pure housekeeping. If another `socket-patch` process is actively running, `repair`\nrefuses up front with `lock_held` (exit 1); it never steals a live lock — wait for the\nother process to finish, or budget a wait with `--lock-timeout`.\n\n**Usage:**\n```bash\nsocket-patch repair [options]\n```\n\n**Command-specific options** (plus all [Global options](#global-options)):\n| Flag | Env var | Description |\n|------|---------|-------------|\n| `--download-only` | `SOCKET_DOWNLOAD_ONLY` | Only download missing artifacts, do not clean up (incompatible with `--offline`). |\n\n**Examples:**\n```bash\n# Full repair (download missing + clean up unused)\nsocket-patch repair\n\n# Cleanup only — missing blobs are warned about and skipped, never downloaded\nsocket-patch repair --offline\n\n# Download missing blobs only\nsocket-patch repair --download-only\n\n# JSON output for scripting\nsocket-patch repair --json\n```\n\n## OpenVEX attestations\n\n`socket-patch vex` turns your local manifest into a machine-readable statement of *which\nknown vulnerabilities no longer affect your build* because a Socket patch has been applied.\nThis lets vulnerability scanners stop flagging CVEs that you've already remediated in\nplace — without bumping the package version.\n\n**How it works**\n\n1. Reads `.socket/manifest.json` and, unless `--no-verify` is passed, re-checks each\n   patched file's hash on disk so the attestation only covers patches that are actually\n   applied. [Vendored](#vendor) patches are verified against the **committed artifact**\n   instead of the installed tree (their impact statement carries a `(vendored)` marker),\n   and need no `setup` install hook to be attested. Detached-vendored patches\n   (`scan --mode vendored --detached`)\n   attest from the vendor ledger's embedded records, and\n   [hosted-mode](#three-patch-modes) patches attest from the redirect ledger\n   (`.socket/vendor/redirect-state.json`, marker `(redirected)` — hash-verified against\n   the installed tree post-install), so `vex` works even with no manifest file at all.\n2. Auto-detects the top-level **product** identifier (override with `--product`), probing\n   in order:\n   - `.git/config` `[remote \"origin\"]` → `pkg:github/<owner>/<repo>` (similar for\n     GitLab/Bitbucket; raw URL otherwise)\n   - `package.json` → `pkg:npm/<name>@<version>`\n   - `pyproject.toml` → `pkg:pypi/<name>@<version>`\n   - `Cargo.toml` → `pkg:cargo/<name>@<version>`\n3. Emits an OpenVEX 0.2.0 document whose statements mark each mitigated vulnerability as\n   `not_affected` (justification: the patch is present), suitable for piping into\n   `vexctl`, Grype, Trivy, and similar tools.\n\n**Provenance markers**\n\nEach statement's impact string records *how* the patch is persisted — one marker per\n[patch mode](#three-patch-modes):\n\n| Impact statement | Mode | What the evidence is | What a consumer should do |\n|---|---|---|---|\n| `Patched via Socket patch <uuid>` | agent | The installed tree: every patched file's hash was verified against the manifest's `afterHash` | Trust the statement as long as the agent install hook (or a CI `apply`) keeps re-applying; ecosystems without a hook must be declared in `setup.manual` |\n| `Patched via Socket patch <uuid> (vendored)` | vendored | The **committed** `.socket/vendor/` artifact was hash-verified — no install hook needed; the lockfile wiring is the persistence mechanism | Trust it on any checkout; the committed bytes are the patch |\n| `Patched via Socket patch <uuid> (redirected)` | hosted | The lockfile's integrity pin points at the Socket-hosted patched package. When emitted in-run by `scan --mode hosted --vex`, the statement is attested **from the redirect ledger without hash verification** (the bytes are fetched at install time — the JSON `vex` summary carries `verified: false`) | Ensure installs still resolve from `patch.socket.dev` (the lockfile edit is intact), and run `socket-patch vex` **after installing** — it re-reads the ledger and hash-verifies the redirected patches against the installed tree |\n\nThe markers are stable strings (see\n[CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md)); scanners and policy engines\nmay match on them.\n\n**Output channels**\n\n| Invocation | VEX document | Status / summary |\n|------------|--------------|------------------|\n| _default_ (no `--output`, no `--json`) | stdout | one-line summary (stderr) |\n| `--output <path>` | the file | one-line summary (stdout) |\n| `--json --output <path>` | the file | machine-readable envelope on stdout (the CI shape) |\n\n`--json` requires `--output`, since the VEX document is itself JSON and would otherwise\ncollide with the envelope on stdout.\n\n**Using it with a scanner**\n\n```bash\n# Generate the attestation as part of CI, then hand it to a scanner\nsocket-patch vex --output socket.vex.json\n\n# Suppress already-patched findings in Grype\ngrype <image-or-dir> --vex socket.vex.json\n\n# Or with Trivy\ntrivy image --vex socket.vex.json <image>\n```\n\nApply patches first (in any mode) — `vex` errors with `no_patches` when there is nothing\nto attest (an empty manifest, no detached-vendored patches, and no hosted redirect\nrecords).\n\n### Inline VEX on `apply` / `scan` / `vendor`\n\nYou don't need a separate `vex` invocation: pass `--vex <path>` to `apply`, `scan`, or\n`vendor` and the same OpenVEX document is generated as a side-effect of a successful run.\n\n```bash\n# Patch and attest in one step\nsocket-patch apply --vex socket.vex.json\n\n# Discover, apply, prune, and attest — the full auto-update-bot pass\nsocket-patch scan --json --mode agent --prune --yes --vex socket.vex.json\n\n# Vendor and attest — works manifest-less with --detached too\nsocket-patch scan --json --mode vendored --yes --vex socket.vex.json\n```\n\nThe `--vex-product`, `--vex-no-verify`, `--vex-doc-id`, and `--vex-compact` flags mirror\nthe standalone command's `--product` / `--no-verify` / `--doc-id` / `--compact` knobs.\n\nContract:\n\n- The document is **always written to the file** (never stdout), so it never collides\n  with the command's own `--json` output. JSON mode adds a top-level `vex` summary —\n  `{ path, statements, format }` — to the envelope (`apply`) / result (`scan`).\n- It's built from the manifest **as it stands after the run** (including any\n  `--mode agent` writes, with or without `--prune`) and verified against on-disk state\n  unless `--vex-no-verify` is set. Generated for real applies, `--dry-run`, and read-only\n  scans alike.\n- **Fail-the-command:** if `--vex` was requested but generation fails (no detectable\n  product, empty/missing manifest, nothing verified, unwritable path), the command exits\n  non-zero **even when the apply/scan itself succeeded**, with a stable error code in the\n  JSON output.\n\n## Scripting & CI/CD\n\nAll commands support `--json` for machine-readable output. JSON responses always include\na `\"status\"` field for easy error detection.\n\n**Authentication in CI:** a runner has no `socket login` state — if your organization\nhas org-tier patches, provide the token as a CI secret via `SOCKET_API_TOKEN` (without\nit, runs silently fall back to the anonymous public proxy and see free patches only, and\npaid-tier blob downloads report `paidRequired`). To deliberately pin a run to the\nanonymous free tier, set `SOCKET_NO_API_TOKEN=1`. See\n[Configuration sources](#configuration-sources).\n\n```bash\n# Check for available patches in CI (read-only)\nresult=$(socket-patch scan --json --ecosystems npm)\npatches=$(echo \"$result\" | jq '.totalPatches')\n\n# Auto-update bot: discover, apply, and garbage-collect in one pass\nsocket-patch scan --json --mode agent --prune --yes | jq '{\n  applied:     [.apply.patches[]? | select(.action == \"added\" or .action == \"updated\") | .purl],\n  pruned:      (.gc.prunedManifestEntries // []),\n  bytes_freed: (.gc.bytesFreed // 0)\n}'\n# The PR action (e.g. peter-evans/create-pull-request) commits the working-tree\n# changes; use this summary as the PR body.\n\n# Apply patches and check result\nsocket-patch apply --json | jq '.status'\n# \"success\", \"partialFailure\", \"noManifest\", or \"error\"\n```\n\nWhen stdin is not a TTY (e.g. in CI pipelines), interactive prompts auto-proceed instead\nof blocking. Progress indicators and ANSI colors are automatically suppressed when output\nis piped.\n\nThe exact JSON shapes, exit codes, and stability guarantees are specified in\n[CLI_CONTRACT.md](crates/socket-patch-cli/CLI_CONTRACT.md).\n\n## Manifest format\n\nDownloaded patches are stored in `.socket/manifest.json`:\n\n```json\n{\n  \"patches\": {\n    \"pkg:npm/package-name@1.0.0\": {\n      \"uuid\": \"unique-patch-id\",\n      \"exportedAt\": \"2024-01-01T00:00:00Z\",\n      \"files\": {\n        \"path/to/file.js\": {\n          \"beforeHash\": \"git-sha256-before\",\n          \"afterHash\": \"git-sha256-after\"\n        }\n      },\n      \"vulnerabilities\": {\n        \"GHSA-xxxx-xxxx-xxxx\": {\n          \"cves\": [\"CVE-2024-12345\"],\n          \"summary\": \"Vulnerability summary\",\n          \"severity\": \"high\",\n          \"description\": \"Detailed description\"\n        }\n      },\n      \"description\": \"Patch description\",\n      \"license\": \"MIT\",\n      \"tier\": \"free\"\n    }\n  }\n}\n```\n\nPatched file contents are in `.socket/blobs/` (named by git SHA256 hash).\n\nThe manifest may also carry an optional top-level `\"setup\"` key persisting setup state —\n`\"setup\": { \"manual\": [\"cargo\"], \"exclude\": [\"packages/legacy\"] }` — where `manual`\nlists ecosystems you patch by hand so [`vex`](#vex) still attests them (see\n[`setup`](#setup)), and `exclude` lists workspace members excluded from setup (written\nby `setup --exclude`).\n\n## Further reading\n\n- **[Ecosystem & platform support](docs/ecosystems.md)** — the full mode × ecosystem\n  matrix, per-ecosystem caveats (Maven, NuGet, Rush monorepos, Go), and supported\n  platforms.\n- **[CLI contract](crates/socket-patch-cli/CLI_CONTRACT.md)** — the machine-readable\n  surface: exact JSON shapes, exit codes, flag/env bindings, and the semver policy that\n  governs them.\n- **[Design notes](docs/design/)** — e.g. [the configuration model](docs/design/configuration.md)\n  and [hosted mode for Go](docs/design/golang-hosted.md) (free tier; the\n  [paid-tier no-go analysis](docs/design/golang-hosted-no-go.md) it supersedes).\n- **[Changelog](CHANGELOG.md)**\n","readmeFilename":"README.md"}