Skip to content

fix(fix): commit every file a fix changes in PR mode - #1571

Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 2 commits into
v1.xfrom
jfblaa/rea-848-socket-cli-socket-fix-pr-mode-drops-files-missing-from
Sep 30, 2026
Merged

Jeppe Fredsgaard Blaabjerg (jfblaa) merged 2 commits into
v1.xfrom
jfblaa/rea-848-socket-cli-socket-fix-pr-mode-drops-files-missing-from

Conversation

@jfblaa

@jfblaa Jeppe Fredsgaard Blaabjerg (jfblaa) commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

LLM Description written by Claude Code:claude-opus-5-5

Fixes REA-848, the socket-cli side of REA-840.

Files coana doesn't report were dropped from fix PRs. PR mode only committed files listed in coana's modifiedFiles, so changes coana wrote without reporting (e.g. package.json override bumps) were left out. Now:

  • every tracked file the fix changes is committed;
  • new untracked files are committed only if coana reports them or they have a manifest name, so build output in repos without a .gitignore stays out;
  • files already dirty before the fix are left out unless coana reports them (keeps generated facts files and local edits out).

This holds with a coana that under-reports, so it doesn't depend on coana-package-manager#2512.

Below the repo root, fixes were skipped as "no changes". git diff --name-only printed repo-root-relative paths while git ls-files, git add and coana use cwd-relative ones. git diff now uses --relative, and both lists use -z.

Tests: PR-mode selection (npm/pnpm transitive override, missing modifiedFiles, pre-dirty files, untracked filtering) and real-git coverage for listing and committing from a subdirectory.

🤖 Generated with Claude Code


Note

Medium Risk
Changes which files land in automated fix PRs and git path handling when cwd is below the repo root; wrong selection could omit fixes or commit unrelated dirty files, though pre-dirty filtering and manifest checks mitigate the latter.

Overview
socket fix PR mode no longer trusts Coana’s modifiedFiles alone. Before each GHSA fix it snapshots the working tree, then selectFixedFiles commits every tracked path that changed unless it was already dirty (local edits and generated facts stay out unless Coana explicitly lists them). That closes gaps such as package.json override bumps Coana applies but omits from modifiedFiles. New untracked files are included only when Coana reports them or the basename matches a scan manifest, so build artifacts in poorly ignored repos are not swept into PRs.

Running fix from a repo subdirectory was broken: unstaged paths from git diff were repo-root-relative while git add and Coana use cwd-relative paths, so fixes looked like “no changes.” gitUnstagedModifiedFiles now uses git diff --relative and both diff and untracked listing parse -z output.

Coverage adds PR-mode commit selection tests and real-git tests for listing and committing from a subdirectory; the changelog records the unreleased fix.

Reviewed by Cursor Bugbot for commit 637869f. Configure here.

PR mode kept only the git-changed paths that coana listed in
modifiedFiles, so anything coana wrote without reporting (e.g.
package.json override bumps) was left out of the PR. Now every tracked
file the fix changes is committed; untracked files still need coana or
a manifest name to vouch for them, and files already dirty before the
fix are left out unless coana reports them.

git diff printed paths relative to the repo root while git ls-files,
git add and coana use cwd-relative paths, so below the repo root the
fix was skipped as "no changes". Use --relative, and -z for both lists.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) merged commit ff18ef1 into v1.x Sep 30, 2026
10 checks passed
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) deleted the jfblaa/rea-848-socket-cli-socket-fix-pr-mode-drops-files-missing-from branch September 30, 2026 11:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants