Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: SocketDev/socket-python-cli
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 536d3a5
Choose a base ref
...
head repository: SocketDev/socket-python-cli
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 860b8ea
Choose a head ref
  • 7 commits
  • 16 files changed
  • 3 contributors

Commits on Sep 8, 2026

  1. chore(deps): bump brotlicffi from 1.2.0.1 to 1.2.0.2 (#340)

    Bumps [brotlicffi](https://github.com/python-hyper/brotlicffi) from 1.2.0.1 to 1.2.0.2.
    - [Changelog](https://github.com/python-hyper/brotlicffi/blob/main/HISTORY.rst)
    - [Commits](python-hyper/brotlicffi@v1.2.0.1...v1.2.0.2)
    
    ---
    updated-dependencies:
    - dependency-name: brotlicffi
      dependency-version: 1.2.0.2
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    9aebab4 View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump the python-minor-patch group across 1 directory wit…

    …h 2 updates (#339)
    
    Bumps the python-minor-patch group with 2 updates in the / directory: [ruff](https://github.com/astral-sh/ruff) and [uv](https://github.com/astral-sh/uv).
    
    
    Updates `ruff` from 0.16.4 to 0.16.5
    - [Release notes](https://github.com/astral-sh/ruff/releases)
    - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/ruff@0.16.4...0.16.5)
    
    Updates `uv` from 0.12.5 to 0.12.8
    - [Release notes](https://github.com/astral-sh/uv/releases)
    - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/uv@0.12.5...0.12.8)
    
    ---
    updated-dependencies:
    - dependency-name: ruff
      dependency-version: 0.16.5
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: uv
      dependency-version: 0.12.7
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    f0b8a9f View commit details
    Browse the repository at this point in the history
  3. ci(deps): bump docker/setup-buildx-action (#338)

    Bumps the github-actions-minor-patch group with 1 update in the /.github/actions/setup-docker directory: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action).
    
    
    Updates `docker/setup-buildx-action` from 4.2.0 to 4.3.0
    - [Release notes](https://github.com/docker/setup-buildx-action/releases)
    - [Commits](docker/setup-buildx-action@bb05f3f...37fe631)
    
    ---
    updated-dependencies:
    - dependency-name: docker/setup-buildx-action
      dependency-version: 4.3.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    dependabot[bot] and lelia authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    86e3c1d View commit details
    Browse the repository at this point in the history

Commits on Sep 9, 2026

  1. chore(deps): bump httpcore2 from 2.9.1 to 2.10.0 (#348)

    Bumps [httpcore2](https://github.com/pydantic/httpx2) from 2.9.1 to 2.10.0.
    - [Release notes](https://github.com/pydantic/httpx2/releases)
    - [Commits](pydantic/httpx2@v2.9.1...v2.10.0)
    
    ---
    updated-dependencies:
    - dependency-name: httpcore2
      dependency-version: 2.10.0
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    9e56d79 View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump httpx2 from 2.10.0 to 2.12.0 (#349)

    Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.10.0 to 2.12.0.
    - [Release notes](https://github.com/pydantic/httpx2/releases)
    - [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
    - [Commits](pydantic/httpx2@v2.10.0...v2.12.0)
    
    ---
    updated-dependencies:
    - dependency-name: httpx2
      dependency-version: 2.12.0
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    e50b3aa View commit details
    Browse the repository at this point in the history
  3. Improve monorepo scan diagnostics and guidance (#325)

    * Improve monorepo scan diagnostics
    
    * Bump version to 2.6.9
    
    * Bump version to 2.7.0
    
    * docs: document the monorepo scan layout trade-off
    
    The mechanics of --sub-path and --workspace-name were documented, but not the
    choice they force. One combined scan gives a single dashboard entry and no
    per-component attribution; one scan per component gives attribution, baselines
    and per-component policy, but adds a repository entry per component, which grows
    the dashboard's repository list. There is no layout that provides both today.
    
    Customers hit this at a dozen-plus components and reasonably assume they have
    configured something wrong. Naming the trade-off, and adding rules of thumb for
    picking a side, is cheaper than each of them discovering it.
    
    Cross-referenced from the CI/CD guide's independent-workspace pattern, which is
    the layout that grows the list.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    ---------
    
    Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
    lelia and claude authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    f65b6af View commit details
    Browse the repository at this point in the history
  4. Normalize Slack issue severity and bump SDK to v3.6.0 (#331)

    * fix(slack): normalize the API's "middle" severity to "medium"
    
    Every severity lookup in the Slack reachability formatter is keyed on "medium",
    but "middle" is what the API sends. A mid-severity finding missed all of them
    at once: uncounted in the summary, excluded from total_findings so the "and N
    more" count can go negative, and sorted at the default order of 4 -- below
    "low" -- so it was truncated out of the message first.
    
    Normalized at the point the alert is read rather than by adding a parallel key
    to each dict, so one canonical spelling flows downstream. The GitLab severity
    map and the PR comment path already accept both forms; this formatter did not.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    * chore(deps): bump socketdev to 3.6.0
    
    Unblocks the pin now that 3.6.0 is on PyPI. SocketPURL_Type gained ten
    members -- alpm, chrome, clawhub, edge-extension, firefox-extension, qpkg,
    socket, swid, vscode and vscode-extension -- and removed none, so artifacts
    of those types stop falling back to "unknown".
    
    No other CLI change is needed: none of the SDK's enum types are imported
    here, and every severity and type lookup already has a default, so the new
    members cannot reach an unguarded branch.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    * ci: only floor the version check at the latest published release
    
    The check required the PR version to exceed both main and PyPI. Comparing
    against main forbids the legitimate case where several PRs ship under one
    unreleased version: the first bumps main, and the rest ride it without
    bumping again so they stay under a single changelog header. Every such PR
    failed, and the only way to green it was a throwaway bump that would strand
    a changelog header on a version that never ships.
    
    PyPI is now the floor, since the real invariant is that a release cannot
    reuse a published version. Main is still a floor in the one direction that
    matters: a PR may leave the version alone or move it forwards, never back.
    Every genuine failure the old check caught -- forgetting to bump, reusing a
    published version, branching from a stale base -- still fails.
    
    Also added this workflow to its own paths filter so a change to the check is
    exercised by the PR that makes it.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    * ci: require pyproject.toml and __init__.py versions to agree
    
    The version lives as two hand-maintained literals with nothing deriving one
    from the other: pyproject.toml is what gets published, and __init__.py is
    what the CLI reports as its User-Agent. Every comparison in this job read
    only __init__.py, so bumping that alone passed the check and then published
    under the old number -- surfacing late, as twine rejecting an existing file,
    after the merge.
    
    Both are now required to match before any other comparison runs. uv.lock
    carries a third copy, but uv derives it and `uv lock --locked` in
    python-tests already fails when it drifts, so it needs no check here.
    
    Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
    
    ---------
    
    Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
    lelia and claude authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    860b8ea View commit details
    Browse the repository at this point in the history
Loading