voidzero-dev / voidzero-dev/setup-vp

Restore SFW blocking tests after Socket API errors are fixed

Open
#161 0 comments 0 reactions 1 assignee View on GitHub

@fengmk2 is already working on this.

Since Sep 16, 2026.

Dominant language
TypeScript
Stars
110
Forks
22
Avg merge
23h 51m
Merged PRs (30d)
26

Description

Restore the SFW malicious-package blocking checks after the Socket alert API failure is resolved.

Upstream report: https://github.com/SocketDev/sfw-free/issues/65.

Temporary skip: #162.

On 2026-09-16, sfw vp install lodahs returned exit code 0 without a block message. This failed the Linux, macOS, and Windows jobs in test-sfw-blocks-malicious, plus the final blocking check in test-sfw-with-socketdev-action.

The failed CI run and retry used Vite+ 0.3.2. The same package and tool versions passed the blocking check on 2026-09-15.

Direct checks with SFW 1.15.1 and 1.15.2 report:

Error occurred: error while fetching package alerts
{"errors":["Malformed Socket API response (Invalid input)"],"purlStrings":["pkg:npm/lodahs@0.0.1-security"]}

The same error occurs with the alternatives crossenv, babelcli, mongose, axois, node-click, and webb3. SFW allows their security placeholder downloads. A benign control, is-odd@3.0.1, produces a normal packageAllowed event. These results indicate a failure in alert handling, so changing the test package does not resolve the failure.

To reproduce without executing package code, run this command with a fresh SFW process:

SFW_DEBUG=true sfw --verbose curl --fail --silent --show-error --max-time 25 \
  https://registry.npmjs.org/lodahs/-/lodahs-0.0.1-security.tgz \
  -o /dev/null

The temporary fix skips the test-sfw-blocks-malicious job and the final malicious-package assertion in test-sfw-with-socketdev-action. The other SFW setup and installation checks remain enabled.

Follow-up:

  • Confirm that SFW can fetch alerts and block a documented test package. Update the pinned SFW version if the upstream fix requires it.
  • Remove both temporary if: ${{ false }} conditions from .github/workflows/test.yml.
  • Confirm a nonzero exit and the package-specific block message on Linux, macOS, and Windows, and through socketdev/action.

Keep both assertions: a network error or registry 404 alone must not count as a successful SFW block.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.