Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
53 commits
Select commit Hold shift + click to select a range
e7fdc4b
chore(deps): bump fgrosse/go-coverage-report
dependabot[bot] Aug 3, 2026
4693ef8
feat(js-pr-validation): add socket.dev supply chain gate
bedatty Aug 5, 2026
cfe360f
fix(js-pr-validation): enforce sfw inspection and purge package cache
bedatty Aug 5, 2026
f75d2fd
fix(js-pr-validation): pin the socketsecurity CLI release
bedatty Aug 5, 2026
ee22bc5
test(js-pr-validation): point socket composites at this branch
bedatty Aug 5, 2026
77b3ad2
feat(js-pr-validation): guard every install and gate on the Socket App
bedatty Aug 5, 2026
5b9ecc6
fix(js-pr-validation): set result-encoding on the socket reporter
bedatty Aug 5, 2026
54f3c4d
fix(js-pr-validation): grant checks:read and stop swallowing API errors
bedatty Aug 5, 2026
bb8ca83
feat(js-pr-validation): declare SOCKET_SECURITY_API_KEY as optional
bedatty Aug 5, 2026
cde744a
test(js-pr-validation): add temporary socket token reachability probe
bedatty Aug 5, 2026
7a33a1e
test(js-pr-validation): drop the socket token reachability probe
bedatty Aug 5, 2026
ef1c887
feat(js-pr-validation): report per-package Socket Firewall findings
bedatty Aug 5, 2026
a778bc2
feat(js-pr-validation): report per-package vulnerabilities via the So…
bedatty Aug 5, 2026
13d8d48
fix(js-pr-validation): surface the Socket API error payload
bedatty Aug 6, 2026
4a53572
fix(js-pr-validation): tell a Cloudflare challenge apart from a scope…
bedatty Aug 6, 2026
4f08039
fix(js-pr-validation): fetch the Socket API with python, not curl
bedatty Aug 6, 2026
de9c860
test(js-pr-validation): widen the socket alert debug sample
bedatty Aug 6, 2026
43ac207
test(js-pr-validation): log the socket alert action distribution
bedatty Aug 6, 2026
b9f61ce
feat(js-pr-validation): filter socket findings by action and own the …
bedatty Aug 6, 2026
52c6a81
feat(js-pr-validation): expose the socket findings policy on the umbr…
bedatty Aug 6, 2026
651aa00
fix(js-pr-validation): render the socket fix object instead of [objec…
bedatty Aug 6, 2026
0f1afd5
feat(js-pr-validation): separate introduced findings from pre-existin…
bedatty Aug 6, 2026
e190d16
test(js-pr-validation): log the socket baseline scan identity
bedatty Aug 6, 2026
d5fa617
fix(js-pr-validation): reject incomplete socket baselines
bedatty Aug 6, 2026
eacae6a
test(js-pr-validation): log the head scan's own scan_state
bedatty Aug 6, 2026
a301f93
fix(js-pr-validation): select the socket baseline by package overlap
bedatty Aug 6, 2026
817e47d
fix(js-pr-validation): attribute findings via Socket's diff scan
bedatty Aug 6, 2026
3ce2df2
feat(js-pr-validation): green header with no new findings, and dashbo…
bedatty Aug 6, 2026
b6365a2
style(js-pr-validation): split the diff-scan lookup across lines
bedatty Aug 6, 2026
6137cc4
feat(js-pr-validation): give the pre-existing section shape
bedatty Aug 6, 2026
ce54891
fix(js-pr-validation): label the scan link as this PR's scan
bedatty Aug 6, 2026
b38f781
feat(js-pr-validation): show which direct dependency reaches a finding
bedatty Aug 6, 2026
cb28c98
chore(release): backmerge main into develop [skip ci]
lerian-studio Aug 7, 2026
87fffd0
fix(js-pr-validation): restore the suggested fixes block
bedatty Aug 7, 2026
b38a179
docs(js-pr-validation): correct the Socket documentation
bedatty Aug 7, 2026
c7ad918
fix(js-pr-validation): detect a stale diff scan instead of trusting it
bedatty Aug 7, 2026
f850c85
fix(js-pr-validation): build the diff scan instead of waiting for the…
bedatty Aug 7, 2026
7d39f39
test(js-pr-validation): diagnose a diff scan reporting added=0
bedatty Aug 7, 2026
10b45f7
fix(js-pr-validation): drop omit_unchanged from the diff scan read
bedatty Aug 7, 2026
95c6f70
fix(js-pr-validation): read the diff buckets from diff_scan.artifacts
bedatty Aug 7, 2026
aaf144c
fix(js-pr-validation): print dashboard URLs instead of bare scan ids
bedatty Aug 7, 2026
c807994
refactor(js-pr-validation): drop the resolved diagnostics
bedatty Aug 7, 2026
b1aa4f4
chore(js-pr-validation): pin the socket composites back to @v1
bedatty Aug 7, 2026
81cc6bf
Merge branch 'develop' into feat/js-pr-validation-socket
bedatty Aug 7, 2026
7b3255f
fix(js-pr-validation): address the CodeRabbit security and correctnes…
bedatty Aug 7, 2026
9f96d77
fix(js-pr-validation): rename anc so the spell check passes
bedatty Aug 7, 2026
cbaa29e
fix(js-pr-validation): close four more silent-pass paths from the review
bedatty Aug 7, 2026
471eb23
fix: remove the typos binary committed by accident
bedatty Aug 7, 2026
513193d
feat(js-pr-validation): add socket.dev supply chain gate (#645)
bedatty Aug 7, 2026
6908449
chore(deps): bump fgrosse/go-coverage-report from 1.3.0 to 1.3.1 in t…
bedatty Aug 7, 2026
b7e5915
fix(go-ci): pin external actions by sha and fix shellcheck warnings
bedatty Aug 7, 2026
c0cced3
fix(js-pr-validation): address socket layer review findings
bedatty Aug 7, 2026
a47239b
fix(js-pr-validation): stop reporting unmeasured socket state as clean
bedatty Aug 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,10 @@ updates:
- "trufflesecurity/trufflehog"
- "anchore/sbom-action"
- "sigstore/cosign-installer"
# Only reachable if SocketDev/action is ever referenced from a workflow;
# its current use is in src/security/socket-firewall, which the
# github-actions ecosystem does not scan (see note at the top).
- "SocketDev/action"
update-types:
- "minor"
- "patch"
Expand Down
352 changes: 99 additions & 253 deletions .github/workflows/frontend-pr-analysis.yml

Large diffs are not rendered by default.

49 changes: 26 additions & 23 deletions .github/workflows/go-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,10 +79,10 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Go
uses: actions/setup-go@v7
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with:
go-version: ${{ matrix.go }}
cache: true
Expand All @@ -101,7 +101,7 @@ jobs:

- name: Upload coverage artifact
if: inputs.enable_coverage_comment && matrix.os == 'ubuntu-latest' && matrix.go == inputs.go_version_lint
uses: actions/upload-artifact@v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: coverage-report
path: coverage.txt
Expand All @@ -118,15 +118,15 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Download coverage artifact
uses: actions/download-artifact@v8
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: coverage-report

- name: Go Coverage Comment
uses: fgrosse/go-coverage-report@v1.3.0
uses: fgrosse/go-coverage-report@e432de98ee94a276e8f666d25bfd76347665f75b # v1.3.1
with:
coverage-artifact-name: coverage-report
coverage-file-name: coverage.txt
Expand All @@ -137,16 +137,16 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Go
uses: actions/setup-go@v7
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with:
go-version: ${{ inputs.go_version_lint }}
cache: true

- name: golangci-lint
uses: golangci/golangci-lint-action@v9
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9
with:
version: ${{ inputs.golangci_lint_version }}
args: ${{ inputs.golangci_lint_args }}
Expand All @@ -159,17 +159,20 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Go
uses: actions/setup-go@v7
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with:
go-version: ${{ inputs.go_version_lint }}
cache: true

- name: Build cross-platform binaries
env:
BUILD_TARGETS: ${{ inputs.build_targets }}
BUILD_PATH: ${{ inputs.build_path }}
run: |
targets='${{ inputs.build_targets }}'
targets="$BUILD_TARGETS"
if [ "$targets" = "[]" ] || [ -z "$targets" ]; then
echo "No build targets specified, using defaults"
targets='[
Expand All @@ -181,21 +184,21 @@ jobs:
]'
fi

echo "$targets" | jq -c '.[]' | while read target; do
os=$(echo $target | jq -r '.os')
arch=$(echo $target | jq -r '.arch')
echo "$targets" | jq -c '.[]' | while read -r target; do
os=$(echo "$target" | jq -r '.os')
arch=$(echo "$target" | jq -r '.arch')
binary_name="${{ github.event.repository.name }}-${os}-${arch}"

if [ "$os" = "windows" ]; then
binary_name="${binary_name}.exe"
fi

echo "Building for $os/$arch..."
GOOS=$os GOARCH=$arch go build -o build/$binary_name ${{ inputs.build_path }}
GOOS="$os" GOARCH="$arch" go build -o "build/$binary_name" "$BUILD_PATH"
done

- name: Upload build artifacts
uses: actions/upload-artifact@v7
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: binaries
path: build/
Expand All @@ -208,10 +211,10 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Go
uses: actions/setup-go@v7
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with:
go-version: ${{ inputs.go_version_lint }}
cache: true
Expand All @@ -227,10 +230,10 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Go
uses: actions/setup-go@v7
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with:
go-version: ${{ inputs.go_version_lint }}
cache: true
Expand All @@ -253,7 +256,7 @@ jobs:

steps:
- name: Checkout code
uses: actions/checkout@v7.0.1
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Check required files
run: |
Expand All @@ -265,7 +268,7 @@ jobs:
test -f LICENSE

- name: Validate Markdown links
uses: tcort/github-action-markdown-link-check@v1
uses: tcort/github-action-markdown-link-check@e047c5b37f24ab722bbef1a27b6fab7f96bc4068 # v1
with:
use-quiet-mode: 'yes'
config-file: '.github/markdown-link-check-config.json'
Expand Down
Loading
Loading