Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Merge origin/main and clarify workspace boundaries
  • Loading branch information
lelia committed Sep 3, 2026
commit a0c571581c2d790564c0f1a173f639662c1f523f
61 changes: 60 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Changelog

## 2.7.0
## 2.8.0

### Changed: improve monorepo scan diagnostics and guidance

Expand All @@ -14,6 +14,65 @@
- Full-scan and streamed-diff API failures now use the configured infrastructure
error exit code instead of the security-finding exit code.

## 2.7.1

### Changed: bump pinned @coana-tech/cli to 15.10.36

- Bumped the pinned reachability engine (`@coana-tech/cli`) from `15.10.32` to
`15.10.36`. See the [Coana changelogs](https://docs.coana.tech/changelogs) for
engine changes.

## 2.7.0

### Fixed: unreadable reachability facts no longer report a blocking package

- Scans with no supported manifest files uploaded a zero-byte `.socket.facts.json`
placeholder. The API cannot parse that, and answers by adding a
`generic/invalid-socket-facts@1.0.0` artifact to the scan, which the CLI then reported
as a new blocking package with no manifest file and no introducing dependency —
failing the run and, on pull requests, leaving a security comment that could not be
acted on. The placeholder is now an empty but well-formed facts document.
- When the API does report `generic/invalid-socket-facts` (a diagnostic for a facts file
it could not parse, not a real dependency), the CLI now excludes it from scan results
and logs a warning instead. It no longer blocks a run, appears in reports, or triggers
a pull request comment.
- Each placeholder is written to its own temporary directory. Two CLI runs sharing a
temporary directory previously used the same path and could remove each other's
placeholder mid-upload.

### Fixed: pull request comments no longer show orphaned tags or an empty table

- Optional sections that rendered as empty, such as the ignore instructions
suppressed by `--disable-ignore`, left a whitespace-only line in the alerts
table. That line closed the surrounding HTML block, and the indented
`</blockquote></details>` tags after it were rendered as a literal code block.
Generated comment markup now omits blank lines and stays under the indentation
that starts a code block.
- Alert descriptions, suggestions and license findings are collapsed onto a
single line so multi-line API text cannot break the table markup either.
- When a pull request has no alerts left to report, the security comment is
replaced with a short confirmation instead of keeping the "Caution" banner
above a table with no rows. This happens both when a later commit resolves
every alert and when every alert is ignored by comment. The comment marker is
preserved, so a commit that reintroduces an alert updates the same comment
rather than posting a second one.
- `@SocketSecurity ignore-all` now applies to comments written by CLI versions
before 2.0.55, which use the older Markdown alerts table. The check was made
once per ignore command, and an ignore-all comment produces none, so no rows
were removed.

### Fixed: `--disable-security-issue` and `--disable-overview` now suppress the comment entirely

- Both flags were checked only after testing whether a comment of that type was
already on the pull request, so they suppressed the first post and then
updated that comment on every later run. `--disable-security-issue` in
particular kept refreshing an existing comment with the full alerts table.
- The flags now mean the CLI does not manage that comment at all. An existing
comment is left untouched rather than being rewritten, since a body claiming
no alerts would be inaccurate when reporting is merely switched off.
- The decision moved into `should_write_comment()` so it is covered directly by
tests.

## 2.6.11

### Changed: bump pinned @coana-tech/cli to 15.10.32
Expand Down
13 changes: 11 additions & 2 deletions docs/ci-cd.md
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,9 @@ when GitHub skips the entire workflow because of a top-level path filter.
Define a repository variable named `SOCKET_MONOREPO_WORKSPACES_JSON`. Its value is
an array with one stable workspace name, one or more scan roots, and the path globs
that should select that workspace. Fill these placeholders with the repository's
real layout; list a shared/root lockfile in every workspace it affects.
real layout. A workspace definition selects directory roots; shared root manifests,
lockfiles, and cross-directory path dependencies outside those roots are not included
automatically.

```json
[
Expand All @@ -94,6 +96,12 @@ real layout; list a shared/root lockfile in every workspace it affects.
]
```

Each `sub_paths` value must be a directory, not an individual manifest or lockfile.
Using `.` includes the entire target path. Do not use this changed-workspace pattern
until the directory boundaries preserve every shared input needed to resolve each
logical graph. If root workspace metadata governs most or all of the repository, a
smaller coverage-preserving split may not be representable with `--sub-path` alone.

Also define `SOCKETCLI_VERSION` as the exact package version validated for the
workflow. The workflow below logs that version, uses full Git history for reliable
base/head selection, creates one matrix job (and therefore one graph and baseline)
Expand Down Expand Up @@ -279,7 +287,8 @@ Each configuration object may intentionally contain several `sub_paths` when
those directories are one logical dependency graph. To split backend resolution,
use separate objects with different `name` values. Add `--workspace <name>` only
when the Socket organization requires API workspace association; it is not a scan
scope control.
scope control. Use `--save-submitted-files-list` in a non-required canary to verify
the exact manifests selected before adopting workspace-level scans as a merge gate.

The job has an explicit 20-minute total budget. Tune that value from observed
workspace-level latency after the split; a five-minute cap can still be too close
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ build-backend = "hatchling.build"

[project]
name = "socketsecurity"
version = "2.7.0"
version = "2.8.0"
requires-python = ">= 3.11"
license = {"file" = "LICENSE"}
dependencies = [
Expand Down
2 changes: 1 addition & 1 deletion socketsecurity/__init__.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
__author__ = 'socket.dev'
__version__ = '2.7.0'
__version__ = '2.8.0'
USER_AGENT = f'SocketPythonCLI/{__version__}'
5 changes: 4 additions & 1 deletion tests/unit/test_socketcli.py
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,10 @@

from socketsecurity import socketcli
from socketsecurity.core.classes import Diff, Package
from socketsecurity.socketcli import build_license_artifact_payload
from socketsecurity.socketcli import (
build_license_artifact_payload,
should_write_comment,
)

# ---------------------------------------------------------------------------
# Exit-code-on-api-error (flag-only, non-breaking for 2.3.x).
Expand Down
2 changes: 1 addition & 1 deletion uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

You are viewing a condensed version of this merge commit. You can view the full changes here.