Skip to content

fix(parsers): accept multi-document pnpm-lock.yaml - #337

Merged
wakemeup0 merged 4 commits into
mainfrom
fix/issue-336
Sep 22, 2026
Merged

wakemeup0 merged 4 commits into
mainfrom
fix/issue-336

Conversation

@wakemeup0

Copy link
Copy Markdown
Contributor

Summary

Closes #336

  • hooray scan project no longer aborts on multi-document pnpm-lock.yaml written by pnpm 12 (lockfileVersion 9: importers in the first document, settings/packages/snapshots in the second).
  • parse_pnpm_lock now iterates every YAML document via serde_yaml::Deserializer, skips empty/non-mapping documents, and unions all top-level mappings (nested mappings merge recursively; scalar/array conflicts keep the first document's value).
  • The YAML alias-expansion budget check is preserved; malformed YAML in any document still fails closed with InputError::Malformed; single-document files produce identical inventory.

Scope

The fix commit is 137d2d76d6bc1e47f1a0086f6de4cd9c050e1225. The PR changes only src/parsers/pnpm.rs relative to main (+216/−3). The branch was brought current by a normal merge of origin/main (chore: merge main into fix/issue-336); no rebase, force-push, or unrelated changes.

Verification already exercised

  • Actual CLI reproduction before fix: hooray scan project . --policy hooray-policy.yaml --offline --format json on the issue's two-document lockfile → exit 2, malformed pnpm-lock.yaml document ... more than one document is not supported.
  • Same run after fix → exit 0; inventory contains lodash@4.17.21 (pkg:npm/lodash@4.17.21, runtime scope) sourced from the second document.
  • Clean control: single-document v9 lockfile → exit 0, identical inventory. Refusal control: [unclosed flow sequence in the second document → exit 2 with a precise syntax diagnostic.
  • cargo test --locked pnpm: 8 passed including 4 new regression tests (two-doc merge, single-doc equivalence, empty-document skip, malformed fail-closed).
  • Coordinator re-ran on the merged head db2c67d05cbc9b1bc81a5f23ddb978caa01c3953: cargo fmt --all -- --check, cargo check --locked --all-targets --all-features, cargo test --locked --all-targets --all-features (656+ tests, 0 failures), cargo clippy --locked --all-targets --all-features -- -D warnings, cargo deny check advisories bans licenses sources — all clean.

Retained local evidence (not checked into this PR):

  • /home/wakemeup/hooray-campaign-evidence/round5-20260922/issue-336.json
  • /home/wakemeup/hooray-campaign-evidence/round5-20260922/queue.sqlite

Limitations and remaining verification

  • Merge semantics: on scalar/array key conflicts across documents the first document wins (pnpm 12 repeats lockfileVersion identically, so no real conflict); non-mapping top-level documents are skipped.
  • cargo llvm-cov was not run locally; the required Checks gate and CodeQL must pass against the published head. This PR is opened only: no merge, admin bypass, force-push, or issue closure was performed.

pnpm 12 writes lockfileVersion 9 files as multiple YAML documents
(importers in the first, settings/packages/snapshots in the second),
which serde_yaml::from_str rejects, aborting the whole scan.

parse_pnpm_lock now iterates every document via
serde_yaml::Deserializer and unions their top-level mappings
recursively, so packages/snapshots/importers accumulate across
documents. Empty documents are skipped, malformed YAML in any
document still fails closed, and the alias-expansion budget check
is preserved. Single-document files produce identical inventory.

Closes #336
@wakemeup0
wakemeup0 merged commit 2f1cd6f into main Sep 22, 2026
6 checks passed
@wakemeup0
wakemeup0 deleted the fix/issue-336 branch September 22, 2026 14:31
wakemeup0 added a commit that referenced this pull request Sep 22, 2026
## 0.9.0 (2026-09-22)

### Features

- **scanners:** IaC checks for docker-compose and GitHub Actions (3a6cbe6)

### Bug Fixes

- **parsers:** resolve lockfile edge, scope, and abort defects from audit (985a893)
- **reports:** harden SBOM ingestion, renderers, model, monitor, and store (362111e)
- **parity:** harden corpus loading, comparison keys, gates, and recording validation (7767d39)
- **parsers:** harden archive readers and expose OCI filesystem builder (99a1f78)
- **engine:** harden OSV matching, graph classification, and input handling (0a5caaa)
- **scanners:** close audit findings in secret, IaC, service-config, SAST, and license (9ec9d45)
- **parsers:** resolve quoted and multi-version Yarn classic dependencies (9a7fa8a)
- **store:** require FULL synchronous for commit durability (35e3491)
- **risk:** rank Unknown severity above Low in severity_points (43cee0a)
- **input:** bound serde_yaml alias expansion on untrusted lockfiles (9a24589)
- **parsers:** accept multi-document pnpm-lock.yaml (#337) (2f1cd6f)

### Other Changes

- **ci:** align dependabot naming with hoolicy policy (#116) (de8f062)
- **parity:** harden recording integrity and corpus coverage assertions (54112a3)
- bump actions/github-script from 8.0.0 to 9.0.0 (#117) (847f10b)
- bump rusqlite from 0.37.0 to 0.40.2 (#118) (776a160)
- bump zstd from 0.13.3 to 0.14.0 (#119) (1c59e21)
- bump toml from 0.9.12+spec-1.1.0 to 1.1.6+spec-1.1.0 (#120) (9ed037b)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

scan project aborts on multi-document pnpm-lock.yaml written by pnpm 12

1 participant