fix(parsers): accept multi-document pnpm-lock.yaml - #337
Merged
Merged
Conversation
pnpm 12 writes lockfileVersion 9 files as multiple YAML documents (importers in the first, settings/packages/snapshots in the second), which serde_yaml::from_str rejects, aborting the whole scan. parse_pnpm_lock now iterates every document via serde_yaml::Deserializer and unions their top-level mappings recursively, so packages/snapshots/importers accumulate across documents. Empty documents are skipped, malformed YAML in any document still fails closed, and the alias-expansion budget check is preserved. Single-document files produce identical inventory. Closes #336
wakemeup0
added a commit
that referenced
this pull request
Sep 22, 2026
## 0.9.0 (2026-09-22) ### Features - **scanners:** IaC checks for docker-compose and GitHub Actions (3a6cbe6) ### Bug Fixes - **parsers:** resolve lockfile edge, scope, and abort defects from audit (985a893) - **reports:** harden SBOM ingestion, renderers, model, monitor, and store (362111e) - **parity:** harden corpus loading, comparison keys, gates, and recording validation (7767d39) - **parsers:** harden archive readers and expose OCI filesystem builder (99a1f78) - **engine:** harden OSV matching, graph classification, and input handling (0a5caaa) - **scanners:** close audit findings in secret, IaC, service-config, SAST, and license (9ec9d45) - **parsers:** resolve quoted and multi-version Yarn classic dependencies (9a7fa8a) - **store:** require FULL synchronous for commit durability (35e3491) - **risk:** rank Unknown severity above Low in severity_points (43cee0a) - **input:** bound serde_yaml alias expansion on untrusted lockfiles (9a24589) - **parsers:** accept multi-document pnpm-lock.yaml (#337) (2f1cd6f) ### Other Changes - **ci:** align dependabot naming with hoolicy policy (#116) (de8f062) - **parity:** harden recording integrity and corpus coverage assertions (54112a3) - bump actions/github-script from 8.0.0 to 9.0.0 (#117) (847f10b) - bump rusqlite from 0.37.0 to 0.40.2 (#118) (776a160) - bump zstd from 0.13.3 to 0.14.0 (#119) (1c59e21) - bump toml from 0.9.12+spec-1.1.0 to 1.1.6+spec-1.1.0 (#120) (9ed037b)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #336
hooray scan projectno longer aborts on multi-documentpnpm-lock.yamlwritten by pnpm 12 (lockfileVersion 9:importersin the first document,settings/packages/snapshotsin the second).parse_pnpm_locknow iterates every YAML document viaserde_yaml::Deserializer, skips empty/non-mapping documents, and unions all top-level mappings (nested mappings merge recursively; scalar/array conflicts keep the first document's value).InputError::Malformed; single-document files produce identical inventory.Scope
The fix commit is
137d2d76d6bc1e47f1a0086f6de4cd9c050e1225. The PR changes onlysrc/parsers/pnpm.rsrelative to main (+216/−3). The branch was brought current by a normal merge oforigin/main(chore: merge main into fix/issue-336); no rebase, force-push, or unrelated changes.Verification already exercised
hooray scan project . --policy hooray-policy.yaml --offline --format jsonon the issue's two-document lockfile → exit 2,malformed pnpm-lock.yaml document ... more than one document is not supported.lodash@4.17.21(pkg:npm/lodash@4.17.21, runtime scope) sourced from the second document.[unclosedflow sequence in the second document → exit 2 with a precise syntax diagnostic.cargo test --locked pnpm: 8 passed including 4 new regression tests (two-doc merge, single-doc equivalence, empty-document skip, malformed fail-closed).db2c67d05cbc9b1bc81a5f23ddb978caa01c3953:cargo fmt --all -- --check,cargo check --locked --all-targets --all-features,cargo test --locked --all-targets --all-features(656+ tests, 0 failures),cargo clippy --locked --all-targets --all-features -- -D warnings,cargo deny check advisories bans licenses sources— all clean.Retained local evidence (not checked into this PR):
/home/wakemeup/hooray-campaign-evidence/round5-20260922/issue-336.json/home/wakemeup/hooray-campaign-evidence/round5-20260922/queue.sqliteLimitations and remaining verification
lockfileVersionidentically, so no real conflict); non-mapping top-level documents are skipped.cargo llvm-covwas not run locally; the requiredChecksgate and CodeQL must pass against the published head. This PR is opened only: no merge, admin bypass, force-push, or issue closure was performed.