-
Notifications
You must be signed in to change notification settings - Fork 10
Comparing changes
Open a pull request
base repository: SocketDev/socket-python-cli
base: v2.9.6
head repository: SocketDev/socket-python-cli
compare: main
- 16 commits
- 21 files changed
- 5 contributors
Commits on Sep 22, 2026
-
chore(deps): bump anyio from 4.12.0 to 4.14.2 (#363)
Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.0 to 4.14.2. - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.12.0...4.14.2) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c866782 - Browse repository at this point
Copy the full SHA c866782View commit details -
chore(deps): bump the python-minor-patch group across 1 directory wit…
…h 2 updates (#360) Bumps the python-minor-patch group with 2 updates in the / directory: [ruff](https://github.com/astral-sh/ruff) and [uv](https://github.com/astral-sh/uv). Updates `ruff` from 0.16.6 to 0.16.7 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.6...0.16.7) Updates `uv` from 0.12.9 to 0.12.15 - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.9...0.12.15) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: uv dependency-version: 0.12.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: lelia <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for ce388c8 - Browse repository at this point
Copy the full SHA ce388c8View commit details
Commits on Sep 23, 2026
-
Bump pinned @coana-tech/cli to 15.10.51 (#370)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7c95310 - Browse repository at this point
Copy the full SHA 7c95310View commit details
Commits on Sep 24, 2026
-
Cap the commit message read from the local checkout (#367)
* Cap the commit message read from the local checkout commit_message travels in the query string of the full scan request, so an oversized value overflows the edge proxy's request line limit and the scan fails before reaching the API. The 200-character cap already covered --commit-message, but a run that omitted the flag backfilled the value straight from the checkout's HEAD commit, uncapped, so repositories whose commit messages carry generated release notes could not be scanned at all. Make the cap an invariant of the parsed configuration rather than a step in flag parsing, and apply it to the git-derived value as well. The truncation helper and its limit move to module scope so both sites share one definition. Extract the git setup block out of main_code into apply_git_context so the backfill is reachable from a test. Behavior is unchanged: the same fields are filled in the same order, and a path that is not a repository still sets ignore_commit_files. Note that the API has no length validation on the field. The rejection comes from the proxy in front of it, which reports 413 or 431 depending on which layer answers; the comment now covers both rather than naming one. * Make truncation visible and name the cause when a request is refused for size Two follow-on safeguards for the same failure, both aimed at CI runs where no one is watching a terminal. Truncation was silent: the notice sat at DEBUG, which a pipeline that does not pass --enable-debug never prints, and the stored value gave no sign it had been clipped. The notice moves to INFO and the value now ends in "...". The 200-character ceiling is unchanged -- the marker replaces the tail rather than extending past it -- so the request line is no larger than before. A request line the proxy refuses comes back as 413, 414 or 431 depending on which limit it checks, carrying the proxy's own response body and nothing about what to change. Those statuses now raise with the cause and the flag to change named, keeping the SDK's original text underneath. None of them were retried before and none are now: the same oversized URL would go back out. Any oversized query parameter is covered, not only the commit message. Buildkite already gets the section markers and the soft_fail hint from _emit_infrastructure_error, which this error reaches like any other API failure, so nothing platform-specific is added here. * Trim the changelog entry and the comments it duplicated Cut the 2.9.7 section to two bullets: what a user of a patch release needs is the behavior they will see, not the mechanism behind it. Reword the comments the entry was echoing so each states a present-tense invariant, and name the same three statuses in both the cap's rationale and the upload path rather than two overlapping subsets. * Clarify ambiguous 413 scan failures
Configuration menu - View commit details
-
Copy full SHA for 325d551 - Browse repository at this point
Copy the full SHA 325d551View commit details -
Detect manifest changes across the whole pull request range, and fix …
…full-scan reporting (#371) * Detect changed files across the whole base..HEAD range Changed-file detection reads a full comparison range only when it recognizes the CI environment: a GitHub pull request, a GitLab merge request, a Bitbucket pull request, or a Buildkite pull request. Every other run falls through to `git show HEAD`, which sees the tip commit alone. That makes dependency gating depend on commit ordering. A pull request whose manifest changed in an earlier commit, followed by a source-only commit, looks like a source-only change: the supported-manifest check fails, the comparison is abandoned for a full scan, and blocking is suppressed, so the run reports no new issues and exits 0. A caller that supplies a base commit has stated the range outright, so honor it ahead of any inference from the environment, reusing the same range detection the recognized providers already use. An unresolvable base commit warns rather than degrading quietly, because the fallback silently narrows the comparison to one commit. * Report full-scan findings as repository findings, not new ones A run with no baseline creates a full scan and suppresses blocking, because there is nothing to compare against and so nothing can be attributed to the change. When an alert-bearing output format is enabled the scan still carries every finding in the repository, and the console summary labeled those `NEW` and their link `Diff Url`. Both are wrong for a full scan, and the first contradicts the exit code: the summary reported blocking issues while the run exited 0, which reads as gating that silently failed rather than gating that correctly did not apply. Label the counts and the link by what the run produced, and say why the counts do not gate. The alert list itself is left alone, since SARIF and JSON output read it and renaming their fields would break consumers. * Stop doubling the namespace in a removed package's purl update_package_values already prefixes a namespaced package's purl with its namespace, so prefixing it again while collecting removed artifacts produced `com.example/[email protected]/com.example/[email protected]`. The purl reaches the dependency overview comment verbatim, so every removed or replaced row for a namespaced package rendered with an unreadable name. The loop collecting added artifacts calls the same function and never did this. * Describe --ignore-commit-files by what it does, and release 2.10.0 The CLI reference described `--ignore-commit-files` as forcing a full scan in four places, and `--help` said only "Ignore commit files". The flag forces a comparison. The confusion is that "full scan" carries two meanings here: the set of files scanned, where the documentation was right, and the scan mode, where it stated the opposite of the behavior. Anyone looking for a way to run a comparison when the changed-file check would skip one would rule out the only flag that does it. Also documents the range that changed-file detection reads, and that supplying a base commit widens it. * Handle explicit base ranges in shallow clones
Configuration menu - View commit details
-
Copy full SHA for 184dc0d - Browse repository at this point
Copy the full SHA 184dc0dView commit details -
Bump pinned @coana-tech/cli to 15.10.54 (#374)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b5d0dd5 - Browse repository at this point
Copy the full SHA b5d0dd5View commit details
Commits on Sep 25, 2026
-
ci(deps): bump the github-actions-minor-patch group across 2 director…
…ies with 3 updates (#376) Bumps the github-actions-minor-patch group with 1 update in the / directory: [docker/build-push-action](https://github.com/docker/build-push-action). Bumps the github-actions-minor-patch group with 2 updates in the /.github/actions/setup-docker directory: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) and [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action). Updates `docker/build-push-action` from 7.3.0 to 7.4.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@53b7df9...c3c9e26) Updates `docker/setup-qemu-action` from 4.3.0 to 4.4.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@1f40c72...9901266) Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@37fe631...f87e599) --- updated-dependencies: - dependency-name: docker/build-push-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-minor-patch - dependency-name: docker/setup-qemu-action dependency-version: 4.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-minor-patch - dependency-name: docker/setup-buildx-action dependency-version: 4.4.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions-minor-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for bdb2938 - Browse repository at this point
Copy the full SHA bdb2938View commit details -
chore(deps): bump the python-minor-patch group with 3 updates (#377)
Bumps the python-minor-patch group with 3 updates: [ruff](https://github.com/astral-sh/ruff), [hatch](https://github.com/pypa/hatch) and [hatchling](https://github.com/pypa/hatch). Updates `ruff` from 0.16.7 to 0.16.8 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.7...0.16.8) Updates `hatch` from 1.18.0 to 1.18.1 - [Release notes](https://github.com/pypa/hatch/releases) - [Commits](pypa/hatch@hatch-v1.18.0...hatch-v1.18.1) Updates `hatchling` from 1.32.0 to 1.32.3 - [Release notes](https://github.com/pypa/hatch/releases) - [Commits](pypa/hatch@hatchling-v1.32.0...hatchling-v1.32.3) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: hatch dependency-version: 1.18.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: hatchling dependency-version: 1.32.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: lelia <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for df7c21a - Browse repository at this point
Copy the full SHA df7c21aView commit details -
Bump pinned @coana-tech/cli to 15.10.55 (#375)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com> Co-authored-by: lelia <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 077cd21 - Browse repository at this point
Copy the full SHA 077cd21View commit details
Commits on Sep 26, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 7d37821 - Browse repository at this point
Copy the full SHA 7d37821View commit details
Commits on Sep 28, 2026
-
Bump pinned @coana-tech/cli to 15.11.3 (#381)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for e523d6c - Browse repository at this point
Copy the full SHA e523d6cView commit details
Commits on Sep 29, 2026
-
Bump pinned @coana-tech/cli to 15.11.4 (#382)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 8bf6f3b - Browse repository at this point
Copy the full SHA 8bf6f3bView commit details
Commits on Sep 30, 2026
-
Detect non-main default branches in single-branch CI checkouts (#383)
* Detect non-main default branches in single-branch CI checkouts actions/checkout fetches one branch and leaves no origin/HEAD. Since 2.6.6 dropped the git fetch --all that recreated origin/HEAD, default-branch detection fell back to main/master, so scans on repos whose default branch is dev never became the branch head. When origin/HEAD is missing, read the default branch from the GitHub event payload, then from git ls-remote --symref origin HEAD, before the main/master fallback. * Bound the remote default-branch lookup on every platform GitPython's kill_after_timeout is rejected on Windows and relies on ps --ppid, which macOS lacks. It also leaves git-remote-https holding the output pipe after the parent dies, so a stalled remote blocked startup past the timeout. Run git ls-remote in its own process group and kill the whole group on timeout, with taskkill /T on Windows. * Read CI default-branch variables in the shared lookup GitLab's CI_DEFAULT_BRANCH and Buildkite's BUILDKITE_PIPELINE_DEFAULT_BRANCH only fed the final branch comparison. The commit-on-default check still went to the remote, so single-branch checkouts on those CIs paid for a git ls-remote call even when CI already knew the answer. Both variables now come first in get_default_branch_name. Also simplifies the remote lookup. start_new_session works on every platform because Windows ignores it and taskkill walks the tree by PID. The stalled-remote fixture is now a listener that never accepts, and the test clears proxy variables so it really waits for the timeout. * Avoid remote default-branch lookup for PR builds --------- Co-authored-by: lelia <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 3eb5433 - Browse repository at this point
Copy the full SHA 3eb5433View commit details -
Bump pinned @coana-tech/cli to 15.11.5 (#384)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for bbe741c - Browse repository at this point
Copy the full SHA bbe741cView commit details
Commits on Oct 2, 2026
-
chore(deps): bump the python-minor-patch group with 3 updates (#385)
* chore(deps): bump the python-minor-patch group with 3 updates Bumps the python-minor-patch group with 3 updates: [ruff](https://github.com/astral-sh/ruff), [uv](https://github.com/astral-sh/uv) and [hatchling](https://github.com/pypa/hatch). Updates `ruff` from 0.16.8 to 0.16.9 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.8...0.16.9) Updates `uv` from 0.12.15 to 0.12.18 - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.15...0.12.18) Updates `hatchling` from 1.32.3 to 1.32.4 - [Release notes](https://github.com/pypa/hatch/releases) - [Commits](pypa/hatch@hatchling-v1.32.3...hatchling-v1.32.4) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: uv dependency-version: 0.12.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-patch - dependency-name: hatchling dependency-version: 1.32.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-patch ... Signed-off-by: dependabot[bot] <[email protected]> * chore(deps): lock urllib3 2.8.0 and virtualenv 21.12.1 to clear dependency-audit pip-audit flags the previously locked transitive versions: - urllib3 2.7.0: PYSEC-2026-4175, -4176, -4177 (fixed in 2.8.0) - virtualenv 21.4.2: PYSEC-2026-4011 to -4014 (fixed in 21.7.11 to 21.7.13) urllib3 is pulled in by requests and twine; virtualenv by hatch and pre-commit (dev only). virtualenv 21.12.1 is the newest release past the 7-day Dependabot cooldown. It requires python-discovery>=1.6, so that moves 1.4.0 -> 1.6.1. --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: lelia <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 5415869 - Browse repository at this point
Copy the full SHA 5415869View commit details -
Bump pinned @coana-tech/cli to 15.11.6 (#386)
Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com> Co-authored-by: lelia <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for fb50eaf - Browse repository at this point
Copy the full SHA fb50eafView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v2.9.6...main