Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: SocketDev/socket-python-cli
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.9.6
Choose a base ref
...
head repository: SocketDev/socket-python-cli
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: main
Choose a head ref
  • 16 commits
  • 21 files changed
  • 5 contributors

Commits on Sep 22, 2026

  1. chore(deps): bump anyio from 4.12.0 to 4.14.2 (#363)

    Bumps [anyio](https://github.com/agronholm/anyio) from 4.12.0 to 4.14.2.
    - [Release notes](https://github.com/agronholm/anyio/releases)
    - [Commits](agronholm/anyio@4.12.0...4.14.2)
    
    ---
    updated-dependencies:
    - dependency-name: anyio
      dependency-version: 4.14.2
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 22, 2026
    Configuration menu
    Copy the full SHA
    c866782 View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump the python-minor-patch group across 1 directory wit…

    …h 2 updates (#360)
    
    Bumps the python-minor-patch group with 2 updates in the / directory: [ruff](https://github.com/astral-sh/ruff) and [uv](https://github.com/astral-sh/uv).
    
    
    Updates `ruff` from 0.16.6 to 0.16.7
    - [Release notes](https://github.com/astral-sh/ruff/releases)
    - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/ruff@0.16.6...0.16.7)
    
    Updates `uv` from 0.12.9 to 0.12.15
    - [Release notes](https://github.com/astral-sh/uv/releases)
    - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/uv@0.12.9...0.12.15)
    
    ---
    updated-dependencies:
    - dependency-name: ruff
      dependency-version: 0.16.7
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: uv
      dependency-version: 0.12.13
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <[email protected]>
    dependabot[bot] and lelia authored Sep 22, 2026
    Configuration menu
    Copy the full SHA
    ce388c8 View commit details
    Browse the repository at this point in the history

Commits on Sep 23, 2026

  1. Bump pinned @coana-tech/cli to 15.10.51 (#370)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    socket-pr-bot[bot] authored Sep 23, 2026
    Configuration menu
    Copy the full SHA
    7c95310 View commit details
    Browse the repository at this point in the history

Commits on Sep 24, 2026

  1. Cap the commit message read from the local checkout (#367)

    * Cap the commit message read from the local checkout
    
    commit_message travels in the query string of the full scan request, so an
    oversized value overflows the edge proxy's request line limit and the scan fails
    before reaching the API. The 200-character cap already covered --commit-message,
    but a run that omitted the flag backfilled the value straight from the checkout's
    HEAD commit, uncapped, so repositories whose commit messages carry generated
    release notes could not be scanned at all.
    
    Make the cap an invariant of the parsed configuration rather than a step in flag
    parsing, and apply it to the git-derived value as well. The truncation helper and
    its limit move to module scope so both sites share one definition.
    
    Extract the git setup block out of main_code into apply_git_context so the
    backfill is reachable from a test. Behavior is unchanged: the same fields are
    filled in the same order, and a path that is not a repository still sets
    ignore_commit_files.
    
    Note that the API has no length validation on the field. The rejection comes from
    the proxy in front of it, which reports 413 or 431 depending on which layer
    answers; the comment now covers both rather than naming one.
    
    * Make truncation visible and name the cause when a request is refused for size
    
    Two follow-on safeguards for the same failure, both aimed at CI runs where no one
    is watching a terminal.
    
    Truncation was silent: the notice sat at DEBUG, which a pipeline that does not
    pass --enable-debug never prints, and the stored value gave no sign it had been
    clipped. The notice moves to INFO and the value now ends in "...". The
    200-character ceiling is unchanged -- the marker replaces the tail rather than
    extending past it -- so the request line is no larger than before.
    
    A request line the proxy refuses comes back as 413, 414 or 431 depending on which
    limit it checks, carrying the proxy's own response body and nothing about what to
    change. Those statuses now raise with the cause and the flag to change named,
    keeping the SDK's original text underneath. None of them were retried before and
    none are now: the same oversized URL would go back out. Any oversized query
    parameter is covered, not only the commit message.
    
    Buildkite already gets the section markers and the soft_fail hint from
    _emit_infrastructure_error, which this error reaches like any other API failure,
    so nothing platform-specific is added here.
    
    * Trim the changelog entry and the comments it duplicated
    
    Cut the 2.9.7 section to two bullets: what a user of a patch release needs is the
    behavior they will see, not the mechanism behind it.
    
    Reword the comments the entry was echoing so each states a present-tense
    invariant, and name the same three statuses in both the cap's rationale and the
    upload path rather than two overlapping subsets.
    
    * Clarify ambiguous 413 scan failures
    lelia authored Sep 24, 2026
    Configuration menu
    Copy the full SHA
    325d551 View commit details
    Browse the repository at this point in the history
  2. Detect manifest changes across the whole pull request range, and fix …

    …full-scan reporting (#371)
    
    * Detect changed files across the whole base..HEAD range
    
    Changed-file detection reads a full comparison range only when it recognizes
    the CI environment: a GitHub pull request, a GitLab merge request, a Bitbucket
    pull request, or a Buildkite pull request. Every other run falls through to
    `git show HEAD`, which sees the tip commit alone.
    
    That makes dependency gating depend on commit ordering. A pull request whose
    manifest changed in an earlier commit, followed by a source-only commit, looks
    like a source-only change: the supported-manifest check fails, the comparison
    is abandoned for a full scan, and blocking is suppressed, so the run reports no
    new issues and exits 0.
    
    A caller that supplies a base commit has stated the range outright, so honor it
    ahead of any inference from the environment, reusing the same range detection
    the recognized providers already use. An unresolvable base commit warns rather
    than degrading quietly, because the fallback silently narrows the comparison to
    one commit.
    
    * Report full-scan findings as repository findings, not new ones
    
    A run with no baseline creates a full scan and suppresses blocking, because
    there is nothing to compare against and so nothing can be attributed to the
    change. When an alert-bearing output format is enabled the scan still carries
    every finding in the repository, and the console summary labeled those `NEW`
    and their link `Diff Url`.
    
    Both are wrong for a full scan, and the first contradicts the exit code: the
    summary reported blocking issues while the run exited 0, which reads as gating
    that silently failed rather than gating that correctly did not apply.
    
    Label the counts and the link by what the run produced, and say why the counts
    do not gate. The alert list itself is left alone, since SARIF and JSON output
    read it and renaming their fields would break consumers.
    
    * Stop doubling the namespace in a removed package's purl
    
    update_package_values already prefixes a namespaced package's purl with its
    namespace, so prefixing it again while collecting removed artifacts produced
    `com.example/[email protected]/com.example/[email protected]`.
    
    The purl reaches the dependency overview comment verbatim, so every removed or
    replaced row for a namespaced package rendered with an unreadable name. The
    loop collecting added artifacts calls the same function and never did this.
    
    * Describe --ignore-commit-files by what it does, and release 2.10.0
    
    The CLI reference described `--ignore-commit-files` as forcing a full scan in
    four places, and `--help` said only "Ignore commit files". The flag forces a
    comparison. The confusion is that "full scan" carries two meanings here: the
    set of files scanned, where the documentation was right, and the scan mode,
    where it stated the opposite of the behavior.
    
    Anyone looking for a way to run a comparison when the changed-file check would
    skip one would rule out the only flag that does it.
    
    Also documents the range that changed-file detection reads, and that supplying
    a base commit widens it.
    
    * Handle explicit base ranges in shallow clones
    lelia authored Sep 24, 2026
    Configuration menu
    Copy the full SHA
    184dc0d View commit details
    Browse the repository at this point in the history
  3. Bump pinned @coana-tech/cli to 15.10.54 (#374)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    socket-pr-bot[bot] authored Sep 24, 2026
    Configuration menu
    Copy the full SHA
    b5d0dd5 View commit details
    Browse the repository at this point in the history

Commits on Sep 25, 2026

  1. ci(deps): bump the github-actions-minor-patch group across 2 director…

    …ies with 3 updates (#376)
    
    Bumps the github-actions-minor-patch group with 1 update in the / directory: [docker/build-push-action](https://github.com/docker/build-push-action).
    Bumps the github-actions-minor-patch group with 2 updates in the /.github/actions/setup-docker directory: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) and [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action).
    
    
    Updates `docker/build-push-action` from 7.3.0 to 7.4.0
    - [Release notes](https://github.com/docker/build-push-action/releases)
    - [Commits](docker/build-push-action@53b7df9...c3c9e26)
    
    Updates `docker/setup-qemu-action` from 4.3.0 to 4.4.0
    - [Release notes](https://github.com/docker/setup-qemu-action/releases)
    - [Commits](docker/setup-qemu-action@1f40c72...9901266)
    
    Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
    - [Release notes](https://github.com/docker/setup-buildx-action/releases)
    - [Commits](docker/setup-buildx-action@37fe631...f87e599)
    
    ---
    updated-dependencies:
    - dependency-name: docker/build-push-action
      dependency-version: 7.4.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/setup-qemu-action
      dependency-version: 4.4.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/setup-buildx-action
      dependency-version: 4.4.1
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 25, 2026
    Configuration menu
    Copy the full SHA
    bdb2938 View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump the python-minor-patch group with 3 updates (#377)

    Bumps the python-minor-patch group with 3 updates: [ruff](https://github.com/astral-sh/ruff), [hatch](https://github.com/pypa/hatch) and [hatchling](https://github.com/pypa/hatch).
    
    
    Updates `ruff` from 0.16.7 to 0.16.8
    - [Release notes](https://github.com/astral-sh/ruff/releases)
    - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/ruff@0.16.7...0.16.8)
    
    Updates `hatch` from 1.18.0 to 1.18.1
    - [Release notes](https://github.com/pypa/hatch/releases)
    - [Commits](pypa/hatch@hatch-v1.18.0...hatch-v1.18.1)
    
    Updates `hatchling` from 1.32.0 to 1.32.3
    - [Release notes](https://github.com/pypa/hatch/releases)
    - [Commits](pypa/hatch@hatchling-v1.32.0...hatchling-v1.32.3)
    
    ---
    updated-dependencies:
    - dependency-name: ruff
      dependency-version: 0.16.8
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: hatch
      dependency-version: 1.18.1
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: hatchling
      dependency-version: 1.32.3
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <[email protected]>
    dependabot[bot] and lelia authored Sep 25, 2026
    Configuration menu
    Copy the full SHA
    df7c21a View commit details
    Browse the repository at this point in the history
  3. Bump pinned @coana-tech/cli to 15.10.55 (#375)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <[email protected]>
    socket-pr-bot[bot] and lelia authored Sep 25, 2026
    Configuration menu
    Copy the full SHA
    077cd21 View commit details
    Browse the repository at this point in the history

Commits on Sep 26, 2026

  1. Configuration menu
    Copy the full SHA
    7d37821 View commit details
    Browse the repository at this point in the history

Commits on Sep 28, 2026

  1. Bump pinned @coana-tech/cli to 15.11.3 (#381)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    socket-pr-bot[bot] authored Sep 28, 2026
    Configuration menu
    Copy the full SHA
    e523d6c View commit details
    Browse the repository at this point in the history

Commits on Sep 29, 2026

  1. Bump pinned @coana-tech/cli to 15.11.4 (#382)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    socket-pr-bot[bot] authored Sep 29, 2026
    Configuration menu
    Copy the full SHA
    8bf6f3b View commit details
    Browse the repository at this point in the history

Commits on Sep 30, 2026

  1. Detect non-main default branches in single-branch CI checkouts (#383)

    * Detect non-main default branches in single-branch CI checkouts
    
    actions/checkout fetches one branch and leaves no origin/HEAD. Since 2.6.6
    dropped the git fetch --all that recreated origin/HEAD, default-branch
    detection fell back to main/master, so scans on repos whose default branch
    is dev never became the branch head.
    
    When origin/HEAD is missing, read the default branch from the GitHub event
    payload, then from git ls-remote --symref origin HEAD, before the
    main/master fallback.
    
    * Bound the remote default-branch lookup on every platform
    
    GitPython's kill_after_timeout is rejected on Windows and relies on
    ps --ppid, which macOS lacks. It also leaves git-remote-https holding the
    output pipe after the parent dies, so a stalled remote blocked startup past
    the timeout.
    
    Run git ls-remote in its own process group and kill the whole group on
    timeout, with taskkill /T on Windows.
    
    * Read CI default-branch variables in the shared lookup
    
    GitLab's CI_DEFAULT_BRANCH and Buildkite's BUILDKITE_PIPELINE_DEFAULT_BRANCH
    only fed the final branch comparison. The commit-on-default check still
    went to the remote, so single-branch checkouts on those CIs paid for a
    git ls-remote call even when CI already knew the answer. Both variables
    now come first in get_default_branch_name.
    
    Also simplifies the remote lookup. start_new_session works on every
    platform because Windows ignores it and taskkill walks the tree by PID.
    The stalled-remote fixture is now a listener that never accepts, and the
    test clears proxy variables so it really waits for the timeout.
    
    * Avoid remote default-branch lookup for PR builds
    
    ---------
    
    Co-authored-by: lelia <[email protected]>
    mtorp and lelia authored Sep 30, 2026
    Configuration menu
    Copy the full SHA
    3eb5433 View commit details
    Browse the repository at this point in the history
  2. Bump pinned @coana-tech/cli to 15.11.5 (#384)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    socket-pr-bot[bot] authored Sep 30, 2026
    Configuration menu
    Copy the full SHA
    bbe741c View commit details
    Browse the repository at this point in the history

Commits on Oct 2, 2026

  1. chore(deps): bump the python-minor-patch group with 3 updates (#385)

    * chore(deps): bump the python-minor-patch group with 3 updates
    
    Bumps the python-minor-patch group with 3 updates: [ruff](https://github.com/astral-sh/ruff), [uv](https://github.com/astral-sh/uv) and [hatchling](https://github.com/pypa/hatch).
    
    
    Updates `ruff` from 0.16.8 to 0.16.9
    - [Release notes](https://github.com/astral-sh/ruff/releases)
    - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/ruff@0.16.8...0.16.9)
    
    Updates `uv` from 0.12.15 to 0.12.18
    - [Release notes](https://github.com/astral-sh/uv/releases)
    - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/uv@0.12.15...0.12.18)
    
    Updates `hatchling` from 1.32.3 to 1.32.4
    - [Release notes](https://github.com/pypa/hatch/releases)
    - [Commits](pypa/hatch@hatchling-v1.32.3...hatchling-v1.32.4)
    
    ---
    updated-dependencies:
    - dependency-name: ruff
      dependency-version: 0.16.9
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: uv
      dependency-version: 0.12.18
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: hatchling
      dependency-version: 1.32.4
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * chore(deps): lock urllib3 2.8.0 and virtualenv 21.12.1 to clear dependency-audit
    
    pip-audit flags the previously locked transitive versions:
    
    - urllib3 2.7.0: PYSEC-2026-4175, -4176, -4177 (fixed in 2.8.0)
    - virtualenv 21.4.2: PYSEC-2026-4011 to -4014 (fixed in 21.7.11 to 21.7.13)
    
    urllib3 is pulled in by requests and twine; virtualenv by hatch and
    pre-commit (dev only). virtualenv 21.12.1 is the newest release past the
    7-day Dependabot cooldown. It requires python-discovery>=1.6, so that moves
    1.4.0 -> 1.6.1.
    
    ---------
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <[email protected]>
    dependabot[bot] and lelia authored Oct 2, 2026
    Configuration menu
    Copy the full SHA
    5415869 View commit details
    Browse the repository at this point in the history
  2. Bump pinned @coana-tech/cli to 15.11.6 (#386)

    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <[email protected]>
    socket-pr-bot[bot] and lelia authored Oct 2, 2026
    Configuration menu
    Copy the full SHA
    fb50eaf View commit details
    Browse the repository at this point in the history
Loading