Skip to content

fix: fail closed when --package-manifest cannot be used - #328

Closed
vibgrate-team wants to merge 2 commits into
mainfrom
cursor/package-manifest-fail-closed-3bea
Closed

vibgrate-team wants to merge 2 commits into
mainfrom
cursor/package-manifest-fail-closed-3bea

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

vg scan --package-manifest <path> used to start the scan even when that path was missing, unreadable, or not a package-version manifest, and the failure could be a stack or a message that echoed loader output.

The command now checks the path before any scan work:

  • A missing path, an unreadable path, and a path that is not a usable package-version manifest (a directory, invalid JSON, JSON in some other shape, or a ZIP with no package-version manifest entry) stop the command, exit non-zero, and print one stable error. The error names the path and asks for a JSON or ZIP package-version manifest.
  • That message does not include file contents, nearby files, unzip output, or the environment.
  • These failures do not write scan artifacts.
  • A readable JSON or ZIP package-version manifest still scans as before.

Related issues

Fixes #283

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

The check runs in the scan command before discovery or artifact writes. A usable manifest is a JSON object with at least one known ecosystem table (or a runtime catalog), or a ZIP whose package-versions.json, manifest.json, or index.json entry has that shape.

Open in Web Open in Cursor 

cursoragent and others added 2 commits October 3, 2026 15:17
A missing, unreadable, or unusable package-version manifest now stops
vg scan before any scan work, exits non-zero, and prints a stable error
that names the path and what to pass instead.

Fixes #283

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
The readable JSON and ZIP cases pass --vulns so the report shows the
advisory carried by the package-version manifest.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: actionable error when --package-manifest path is missing or unreadable

2 participants