v5: drop PyPI and RubyGems distributions - #298
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit intoSep 30, 2026
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
Mikola Lysenko (mikolalysenko) merged 1 commit into
Conversation
Mikola Lysenko (mikolalysenko)
force-pushed
the
v5/simplify-distributions
branch
from
September 30, 2026 08:41
bd40e28 to
550e6b7
Compare
Mikola Lysenko (mikolalysenko)
merged commit Sep 30, 2026
31c0ae4
into
release/v5-prerelease
59 of 64 checks passed
Mikola Lysenko (mikolalysenko)
deleted the
v5/simplify-distributions
branch
September 30, 2026 08:44
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Targets
release/v5-prerelease(#277).v5 now ships through three distributions: standalone binaries via
install.socket.dev/patch(preferred), Cargo crates, and npm. npm remains available for the official Socket CLI. This removes the maintenance burden of publishing Python and Ruby wrappers while preserving Python and Ruby dependency patching and its compatibility coverage.Validation
scripts/release-lint.sh --sync-onlypassed. In a temporary checkout,scripts/bump-version.sh 5.0.0synchronized Cargo, all 15 npm packages, the npm lockfile, and release notes; the fullscripts/release-lint.sh 5.0.0gate passed.scripts/install.shbyte for byte.git diff --check, and actionlint for release/publish/version-bump workflows passed.ci.ymlhas 45 existing actionlint matrix-property diagnostics on the v5 base. Comparing diagnostics before and after this change found no additions.Note
Medium Risk
Large removal of publish paths and install channels affects every release and existing pip/gem users, though behavior is documented and covered by updated channel/migration tests.
Overview
v5 narrows how the CLI is shipped: standalone binaries (
install.socket.dev/patch), Cargo, and npm only. PyPI wheels, RubyGems launcher/bundler gems, their sources, tests,build-pypi-wheels.py, andpublish-pypi.yml/publish-rubygems.ymlare removed.Release and CI now fan out only to crates.io and npm (
release.ymldropspypi-publish/rubygems-publishjobs).version-sync.sh,release-lint, and bump scripts no longer touch Python/Ruby packaging. CI drops Ruby gem syntax checks and PyPI dispatch tests; ecosystem lint focuses on the installer and Python harness tests.User-facing docs (README, CHANGELOG, releasing runbook, CLI contract) promote the curl installer and add migration steps for
pip/gemusers and old install hooks.Self-update still detects legacy
site-packagesand gem launcher cache paths but refuses in-place updates and prints uninstall + standalone installer (Unix) or global npm (Windows) instead ofpip install --upgrade/gem update.Reviewed by Cursor Bugbot for commit bd40e28. Configure here.