Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: SocketDev/socket-basics
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.1.0
Choose a base ref
...
head repository: SocketDev/socket-basics
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v2.2.0
Choose a head ref
  • 5 commits
  • 22 files changed
  • 2 contributors

Commits on Jul 29, 2026

  1. chore(deps): bump the python-minor-patch group with 4 updates (#90)

    Bumps the python-minor-patch group with 4 updates: [tabulate](https://github.com/astanin/python-tabulate), [socketdev](https://github.com/SocketDev/socket-sdk-python), [pytest](https://github.com/pytest-dev/pytest) and [pytest-cov](https://github.com/pytest-dev/pytest-cov).
    
    
    Updates `tabulate` from 0.9.0 to 0.10.0
    - [Changelog](https://github.com/astanin/python-tabulate/blob/master/CHANGELOG)
    - [Commits](astanin/python-tabulate@v0.9.0...v0.10.0)
    
    Updates `socketdev` from 3.0.29 to 3.3.0
    - [Release notes](https://github.com/SocketDev/socket-sdk-python/releases)
    - [Commits](SocketDev/socket-sdk-python@v3.0.29...v3.3.0)
    
    Updates `pytest` from 9.0.3 to 9.1.1
    - [Release notes](https://github.com/pytest-dev/pytest/releases)
    - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
    - [Commits](pytest-dev/pytest@9.0.3...9.1.1)
    
    Updates `pytest-cov` from 7.0.0 to 7.1.0
    - [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
    - [Commits](pytest-dev/pytest-cov@v7.0.0...v7.1.0)
    
    ---
    updated-dependencies:
    - dependency-name: tabulate
      dependency-version: 0.10.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    - dependency-name: socketdev
      dependency-version: 3.3.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    - dependency-name: pytest
      dependency-version: 9.1.1
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    - dependency-name: pytest-cov
      dependency-version: 7.1.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 29, 2026
    Configuration menu
    Copy the full SHA
    1469c40 View commit details
    Browse the repository at this point in the history
  2. ci(deps): bump the github-actions-minor-patch group across 2 director…

    …ies with 5 updates (#89)
    
    Bumps the github-actions-minor-patch group with 5 updates in the / directory:
    
    | Package | From | To |
    | --- | --- | --- |
    | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.1.0` | `4.2.0` |
    | [docker/login-action](https://github.com/docker/login-action) | `4.2.0` | `4.4.0` |
    | [docker/metadata-action](https://github.com/docker/metadata-action) | `6.1.0` | `6.2.0` |
    | [docker/build-push-action](https://github.com/docker/build-push-action) | `7.2.0` | `7.3.0` |
    | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` |
    
    Bumps the github-actions-minor-patch group with 1 update in the /.github/actions/setup-sfw directory: [actions/setup-python](https://github.com/actions/setup-python).
    
    
    Updates `docker/setup-buildx-action` from 4.1.0 to 4.2.0
    - [Release notes](https://github.com/docker/setup-buildx-action/releases)
    - [Commits](docker/setup-buildx-action@d7f5e7f...bb05f3f)
    
    Updates `docker/login-action` from 4.2.0 to 4.4.0
    - [Release notes](https://github.com/docker/login-action/releases)
    - [Commits](docker/login-action@650006c...af1e73f)
    
    Updates `docker/metadata-action` from 6.1.0 to 6.2.0
    - [Release notes](https://github.com/docker/metadata-action/releases)
    - [Commits](docker/metadata-action@80c7e94...dc80280)
    
    Updates `docker/build-push-action` from 7.2.0 to 7.3.0
    - [Release notes](https://github.com/docker/build-push-action/releases)
    - [Commits](docker/build-push-action@f9f3042...53b7df9)
    
    Updates `actions/setup-python` from 6.2.0 to 6.3.0
    - [Release notes](https://github.com/actions/setup-python/releases)
    - [Commits](actions/setup-python@v6.2.0...ece7cb0)
    
    Updates `actions/setup-python` from 6.2.0 to 6.3.0
    - [Release notes](https://github.com/actions/setup-python/releases)
    - [Commits](actions/setup-python@v6.2.0...ece7cb0)
    
    ---
    updated-dependencies:
    - dependency-name: docker/setup-buildx-action
      dependency-version: 4.2.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/login-action
      dependency-version: 4.4.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/metadata-action
      dependency-version: 6.2.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/build-push-action
      dependency-version: 7.3.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: actions/setup-python
      dependency-version: 6.3.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: actions/setup-python
      dependency-version: 6.3.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 29, 2026
    Configuration menu
    Copy the full SHA
    cb45486 View commit details
    Browse the repository at this point in the history
  3. ci(deps): bump the github-actions-major group across 1 directory with…

    … 2 updates (#91)
    
    Bumps the github-actions-major group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [actions/upload-artifact](https://github.com/actions/upload-artifact).
    
    
    Updates `actions/checkout` from 6.0.2 to 7.0.0
    - [Release notes](https://github.com/actions/checkout/releases)
    - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
    - [Commits](actions/checkout@de0fac2...9c091bb)
    
    Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
    - [Release notes](https://github.com/actions/upload-artifact/releases)
    - [Commits](actions/upload-artifact@ea165f8...043fb46)
    
    ---
    updated-dependencies:
    - dependency-name: actions/checkout
      dependency-version: 7.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: github-actions-major
    - dependency-name: actions/upload-artifact
      dependency-version: 7.0.1
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: github-actions-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 29, 2026
    Configuration menu
    Copy the full SHA
    def178e View commit details
    Browse the repository at this point in the history
  4. chore(deps): bump black in the python-major group across 1 directory (#…

    …92)
    
    Bumps the python-major group with 1 update in the / directory: [black](https://github.com/psf/black).
    
    
    Updates `black` from 25.1.0 to 26.5.1
    - [Release notes](https://github.com/psf/black/releases)
    - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
    - [Commits](psf/black@25.1.0...26.5.1)
    
    ---
    updated-dependencies:
    - dependency-name: black
      dependency-version: 26.5.1
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: python-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 29, 2026
    Configuration menu
    Copy the full SHA
    fb86cda View commit details
    Browse the repository at this point in the history

Commits on Jul 30, 2026

  1. ci: publish multi-arch Docker image variants (#85)

    * ci: publish multi-arch Docker images
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * ci: publish socket-basics heavy image
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * docs(changelog): add 2.1.0 release notes
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * fix(ci): harden Docker release publishing
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * fix(ci): address Docker publish review findings
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * fix(ci): harden Docker manifest publishing
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * fix(ci): publish heavy variant as tag suffix in the shared repo
    
    All image variants now publish to the single socket-basics repository per
    registry, distinguished by tag suffix (2.1.0 vs 2.1.0-heavy) instead of a
    separate socket-basics-heavy repository. This follows the standard Docker
    variant convention (like :slim/:alpine), requires no new Docker Hub repo,
    token rescoping, or GHCR package visibility changes, and makes retiring
    the POC variant trivial.
    
    - _docker-pipeline.yml: new push_name input decouples the registry repo
      from the local build/artifact name
    - publish-docker.yml: merge-manifests iterates variants with a tag_suffix,
      tags via metadata-action flavor suffix, and inspects both suffixed tags
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * fix: move unreleased changelog entries out of the shipped 2.1.0 section
    
    v2.1.0 was released from main with different content; this PR's entries
    now sit under [Unreleased] and get stamped as 2.2.0 at release time.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * fix: correct 2.1.0 changelog date to actual release date (2026-07-22)
    
    The 2026-06-02 date reflected when the bundled commits were authored,
    not when v2.1.0 was actually tagged and released.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * chore(release): prep v2.2.0 — stamp changelog, bump version files and action image ref
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * ci: gate publishing on version files matching the release tag
    
    Restores the guarantee lost when .hooks/version-check.py was removed in
    #46: resolve-version now fails fast if version.py, pyproject.toml, or
    the action.yml image tag disagree with the tag being published.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * feat(scripts): add prep_release.py for mechanical release-prep PRs
    
    One command bumps version.py, pyproject.toml, action.yml, refreshes
    uv.lock, and stamps the [Unreleased] changelog section — so the final
    release PR is a five-file diff that always satisfies the publish
    workflow's version gate. Validates everything before writing anything;
    a failure leaves the tree untouched.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * fix(release): sync __init__.py version and derive bumps from pyproject
    
    The sync_release_version.py check from main caught socket_basics/
    __init__.py still at 2.0.3 — a duplicate version field prep_release.py
    didn't know about. prep_release.py now bumps only pyproject.toml (the
    canonical source) and delegates derived files to sync_release_version.py
    so the two scripts can never disagree. The publish version gate also
    checks __init__.py now.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * fix(core-tool-watch): opt into fail-closed purl batch semantics
    
    The batch purl endpoints default to fail-open: inputs with pending or
    failed resolution are silently omitted unless the caller opts in. Fresh
    pins (socketdev 3.3.0) fell into that omission path and tripped the
    unverified-pin guard with a misleading message.
    
    - purl.post now sends poll=true + timeoutSec=120 + alerts=true (extra
      kwargs pass through as query params on SDK 3.0.29 and 3.3.0)
    - client timeout raised 60->180s so the bounded server poll can finish
    - synthetic pendingScan/notFound rows are mapped to a status field
      before severity classification (never through MALWARE_ALERT_TYPES /
      CRITICAL_SEVERITIES) and fail closed with distinct, precise messages
    - OpenGrep's pkg:github coverage-gap exemption carries over: its pin
      now returns a notFound row instead of being omitted, and stays exempt
    - log the endpoint choice + org slug for forensics
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * docs: changelog entry for core-tool-watch fail-closed purl fix
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * fix(core-tool-watch): calibrate alert thresholds for the full alert set
    
    alerts=true exposed the complete informational alert firehose for the
    first time (the old fail-open responses carried no alert data, so the
    malware gate never actually saw alerts). Calibrated against real batch
    data from run 30504424787:
    
    - drop capability/heuristic signals from MALWARE_ALERT_TYPES:
      shellAccess fires on all four tools (security CLIs spawn
      subprocesses), gptMalware/gptSecurity/obfuscatedFile fire on the
      OpenGrep repo artifact (SAST engines bundle malicious-looking test
      fixtures by design)
    - hard-fail severity gate is critical-only; high-severity rows (cve on
      trivy, gpt heuristics) stay visible in the report for human review
    
    Verified: replaying the failing run's report through the new rules
    yields green while keeping true compromise signals fail-worthy.
    
    ---------
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    lelia authored Jul 30, 2026
    Configuration menu
    Copy the full SHA
    0d3f141 View commit details
    Browse the repository at this point in the history
Loading