-
Notifications
You must be signed in to change notification settings - Fork 0
fix(release): develop to main #659
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Changes from 50 commits
Commits
Show all changes
53 commits
Select commit
Hold shift + click to select a range
e7fdc4b
chore(deps): bump fgrosse/go-coverage-report
dependabot[bot] 4693ef8
feat(js-pr-validation): add socket.dev supply chain gate
bedatty cfe360f
fix(js-pr-validation): enforce sfw inspection and purge package cache
bedatty f75d2fd
fix(js-pr-validation): pin the socketsecurity CLI release
bedatty ee22bc5
test(js-pr-validation): point socket composites at this branch
bedatty 77b3ad2
feat(js-pr-validation): guard every install and gate on the Socket App
bedatty 5b9ecc6
fix(js-pr-validation): set result-encoding on the socket reporter
bedatty 54f3c4d
fix(js-pr-validation): grant checks:read and stop swallowing API errors
bedatty bb8ca83
feat(js-pr-validation): declare SOCKET_SECURITY_API_KEY as optional
bedatty cde744a
test(js-pr-validation): add temporary socket token reachability probe
bedatty 7a33a1e
test(js-pr-validation): drop the socket token reachability probe
bedatty ef1c887
feat(js-pr-validation): report per-package Socket Firewall findings
bedatty a778bc2
feat(js-pr-validation): report per-package vulnerabilities via the So…
bedatty 13d8d48
fix(js-pr-validation): surface the Socket API error payload
bedatty 4a53572
fix(js-pr-validation): tell a Cloudflare challenge apart from a scope…
bedatty 4f08039
fix(js-pr-validation): fetch the Socket API with python, not curl
bedatty de9c860
test(js-pr-validation): widen the socket alert debug sample
bedatty 43ac207
test(js-pr-validation): log the socket alert action distribution
bedatty b9f61ce
feat(js-pr-validation): filter socket findings by action and own the …
bedatty 52c6a81
feat(js-pr-validation): expose the socket findings policy on the umbr…
bedatty 651aa00
fix(js-pr-validation): render the socket fix object instead of [objec…
bedatty 0f1afd5
feat(js-pr-validation): separate introduced findings from pre-existin…
bedatty e190d16
test(js-pr-validation): log the socket baseline scan identity
bedatty d5fa617
fix(js-pr-validation): reject incomplete socket baselines
bedatty eacae6a
test(js-pr-validation): log the head scan's own scan_state
bedatty a301f93
fix(js-pr-validation): select the socket baseline by package overlap
bedatty 817e47d
fix(js-pr-validation): attribute findings via Socket's diff scan
bedatty 3ce2df2
feat(js-pr-validation): green header with no new findings, and dashbo…
bedatty b6365a2
style(js-pr-validation): split the diff-scan lookup across lines
bedatty 6137cc4
feat(js-pr-validation): give the pre-existing section shape
bedatty ce54891
fix(js-pr-validation): label the scan link as this PR's scan
bedatty b38f781
feat(js-pr-validation): show which direct dependency reaches a finding
bedatty cb28c98
chore(release): backmerge main into develop [skip ci]
lerian-studio 87fffd0
fix(js-pr-validation): restore the suggested fixes block
bedatty b38a179
docs(js-pr-validation): correct the Socket documentation
bedatty c7ad918
fix(js-pr-validation): detect a stale diff scan instead of trusting it
bedatty f850c85
fix(js-pr-validation): build the diff scan instead of waiting for the…
bedatty 7d39f39
test(js-pr-validation): diagnose a diff scan reporting added=0
bedatty 10b45f7
fix(js-pr-validation): drop omit_unchanged from the diff scan read
bedatty 95c6f70
fix(js-pr-validation): read the diff buckets from diff_scan.artifacts
bedatty aaf144c
fix(js-pr-validation): print dashboard URLs instead of bare scan ids
bedatty c807994
refactor(js-pr-validation): drop the resolved diagnostics
bedatty b1aa4f4
chore(js-pr-validation): pin the socket composites back to @v1
bedatty 81cc6bf
Merge branch 'develop' into feat/js-pr-validation-socket
bedatty 7b3255f
fix(js-pr-validation): address the CodeRabbit security and correctnes…
bedatty 9f96d77
fix(js-pr-validation): rename anc so the spell check passes
bedatty cbaa29e
fix(js-pr-validation): close four more silent-pass paths from the review
bedatty 471eb23
fix: remove the typos binary committed by accident
bedatty 513193d
feat(js-pr-validation): add socket.dev supply chain gate (#645)
bedatty 6908449
chore(deps): bump fgrosse/go-coverage-report from 1.3.0 to 1.3.1 in t…
bedatty b7e5915
fix(go-ci): pin external actions by sha and fix shellcheck warnings
bedatty c0cced3
fix(js-pr-validation): address socket layer review findings
bedatty a47239b
fix(js-pr-validation): stop reporting unmeasured socket state as clean
bedatty File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.