Restore the SFW malicious-package blocking checks after the Socket alert API failure is resolved.
Upstream report: SocketDev/sfw-free#65.
Temporary skip: #162.
On 2026-09-16, sfw vp install lodahs returned exit code 0 without a block message. This failed the Linux, macOS, and Windows jobs in test-sfw-blocks-malicious, plus the final blocking check in test-sfw-with-socketdev-action.
The failed CI run and retry used Vite+ 0.3.2. The same package and tool versions passed the blocking check on 2026-09-15.
Direct checks with SFW 1.15.1 and 1.15.2 report:
Error occurred: error while fetching package alerts
{"errors":["Malformed Socket API response (Invalid input)"],"purlStrings":["pkg:npm/lodahs@0.0.1-security"]}
The same error occurs with the alternatives crossenv, babelcli, mongose, axois, node-click, and webb3. SFW allows their security placeholder downloads. A benign control, is-odd@3.0.1, produces a normal packageAllowed event. These results indicate a failure in alert handling, so changing the test package does not resolve the failure.
To reproduce without executing package code, run this command with a fresh SFW process:
SFW_DEBUG=true sfw --verbose curl --fail --silent --show-error --max-time 25 \
https://registry.npmjs.org/lodahs/-/lodahs-0.0.1-security.tgz \
-o /dev/null
The temporary fix skips the test-sfw-blocks-malicious job and the final malicious-package assertion in test-sfw-with-socketdev-action. The other SFW setup and installation checks remain enabled.
Follow-up:
Keep both assertions: a network error or registry 404 alone must not count as a successful SFW block.
Restore the SFW malicious-package blocking checks after the Socket alert API failure is resolved.
Upstream report: SocketDev/sfw-free#65.
Temporary skip: #162.
On 2026-09-16,
sfw vp install lodahsreturned exit code0without a block message. This failed the Linux, macOS, and Windows jobs intest-sfw-blocks-malicious, plus the final blocking check intest-sfw-with-socketdev-action.The failed CI run and retry used Vite+
0.3.2. The same package and tool versions passed the blocking check on 2026-09-15.Direct checks with SFW
1.15.1and1.15.2report:The same error occurs with the alternatives
crossenv,babelcli,mongose,axois,node-click, andwebb3. SFW allows their security placeholder downloads. A benign control,is-odd@3.0.1, produces a normalpackageAllowedevent. These results indicate a failure in alert handling, so changing the test package does not resolve the failure.To reproduce without executing package code, run this command with a fresh SFW process:
The temporary fix skips the
test-sfw-blocks-maliciousjob and the final malicious-package assertion intest-sfw-with-socketdev-action. The other SFW setup and installation checks remain enabled.Follow-up:
if: ${{ false }}conditions from.github/workflows/test.yml.socketdev/action.Keep both assertions: a network error or registry
404alone must not count as a successful SFW block.