Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: SocketDev/socket-sdk-python
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v3.0.29
Choose a base ref
...
head repository: SocketDev/socket-sdk-python
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v3.3.0
Choose a head ref
  • 19 commits
  • 28 files changed
  • 11 contributors

Commits on Feb 25, 2026

  1. Bump urllib3 from 2.6.2 to 2.6.3 (#67)

    Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.2 to 2.6.3.
    - [Release notes](https://github.com/urllib3/urllib3/releases)
    - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
    - [Commits](urllib3/urllib3@2.6.2...2.6.3)
    
    ---
    updated-dependencies:
    - dependency-name: urllib3
      dependency-version: 2.6.3
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Feb 25, 2026
    Configuration menu
    Copy the full SHA
    f29af4f View commit details
    Browse the repository at this point in the history
  2. Bump virtualenv from 20.35.4 to 20.36.1 (#66)

    Bumps [virtualenv](https://github.com/pypa/virtualenv) from 20.35.4 to 20.36.1.
    - [Release notes](https://github.com/pypa/virtualenv/releases)
    - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
    - [Commits](pypa/virtualenv@20.35.4...20.36.1)
    
    ---
    updated-dependencies:
    - dependency-name: virtualenv
      dependency-version: 20.36.1
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Feb 25, 2026
    Configuration menu
    Copy the full SHA
    9f8266c View commit details
    Browse the repository at this point in the history
  3. Bump cryptography from 46.0.3 to 46.0.5 (#69)

    Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.3 to 46.0.5.
    - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
    - [Commits](pyca/cryptography@46.0.3...46.0.5)
    
    ---
    updated-dependencies:
    - dependency-name: cryptography
      dependency-version: 46.0.5
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Feb 25, 2026
    Configuration menu
    Copy the full SHA
    7e0ee56 View commit details
    Browse the repository at this point in the history

Commits on Feb 26, 2026

  1. Add workspace param support (#68)

    * Add workspace to FullScanParams for API support
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Add test to verify that workspace is included in query string on FullScanParams
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Update README to document workspace parameter
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Increment version number
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Update tests to use generic data
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Bump version again
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Update pyproject classifiers
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    * Pin python and virutalenv versions for workflows
    
    Signed-off-by: lelia <lelia@socket.dev>
    
    ---------
    
    Signed-off-by: lelia <lelia@socket.dev>
    lelia authored Feb 26, 2026
    Configuration menu
    Copy the full SHA
    ec8940a View commit details
    Browse the repository at this point in the history
  2. Update CODEOWNERS to reflect team ownership (#70)

    Signed-off-by: lelia <lelia@socket.dev>
    lelia authored Feb 26, 2026
    Configuration menu
    Copy the full SHA
    821a777 View commit details
    Browse the repository at this point in the history

Commits on Feb 27, 2026

  1. Configuration menu
    Copy the full SHA
    ed38c65 View commit details
    Browse the repository at this point in the history

Commits on Mar 20, 2026

  1. add context7.json

    ahmadnassri authored Mar 20, 2026
    Configuration menu
    Copy the full SHA
    b3a8d0c View commit details
    Browse the repository at this point in the history

Commits on Mar 25, 2026

  1. fix: harden GitHub Actions workflows (zizmor) (#72)

    - Fix template injection vulnerabilities in release.yml by using
      environment variables instead of direct interpolation of github.ref_name
    - Upgrade actions/checkout to v6.0.2 (pinned to SHA) across all workflows
    - Add persist-credentials: false to all checkout steps
    - Add top-level permissions block to version-check.yml
    
    Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
    reberhardt7 and claude authored Mar 25, 2026
    Configuration menu
    Copy the full SHA
    c8efa8f View commit details
    Browse the repository at this point in the history

Commits on Apr 24, 2026

  1. fix: tolerate unknown SocketCategory values in SocketAlert.from_dict (#…

    …79)
    
    * fix: tolerate unknown SocketCategory values in SocketAlert.from_dict
    
    The Socket API can emit category values the SDK does not yet know about
    (e.g. "other"). Strict enum construction in SocketAlert.from_dict turned
    that into a hard failure that propagated up through stream_diff and
    crashed any consumer that happened to receive such an alert.
    
    Fall back to SocketCategory.MISCELLANEOUS and log a warning when the
    value is unrecognized, so the SDK stays forward-compatible with new
    server-side categories without needing a coordinated release.
    
    Fixes #78.
    
    * chore: bump version to 3.0.33
    dc-larsen authored Apr 24, 2026
    Configuration menu
    Copy the full SHA
    065407a View commit details
    Browse the repository at this point in the history

Commits on May 21, 2026

  1. Support org-scoped batch package endpoint (#76)

    * Add org slug param with org-scoped routing, deprecation warning
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * Add org-scoped + legacy endpoint test coverage, bump lodash placeholders
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * Bump version for minor release rev
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * Fix github project homepage on PyPI
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * Fix RST formatting for title underlines
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    ---------
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    Co-authored-by: Eric Hibbs <eric@socket.dev>
    lelia and flowstate authored May 21, 2026
    Configuration menu
    Copy the full SHA
    41039a8 View commit details
    Browse the repository at this point in the history

Commits on May 22, 2026

  1. ci(version-check): require uv.lock sync alongside pyproject changes (#82

    )
    
    * ci(version-check): require uv.lock sync alongside pyproject changes
    
    Resolves CE-202. Mirrors the workflow + script changes from
    socket-python-cli#204 so the SDK catches lockfile drift the same way
    the CLI now does:
    
    - workflow: trigger paths drop unused setup.py, add uv.lock; new step
      fails CI if pyproject.toml is modified without uv.lock.
    - sync_version.py: new run_uv_lock() helper runs 'uv lock' and signals
      whether the lockfile changed. Wired into all three exit paths
      (--dev auto-bump, normal auto-bump, already-bumped) so the hook
      either updates uv.lock for you or tells you to commit it.
    
    * ci(version-check): also require PR version > latest PyPI stable
    
    Mirrors socket-python-cli's fix at 0462b77 (in PR #199). The workflow
    previously only compared the PR version against main, which missed
    the case where the same or newer version had already been published
    to PyPI — that would slip through CI and either collide on publish
    or leave PyPI ahead of the repo.
    
    - workflow: hits pypi.org/pypi/socketdev/json, filters to stable
      (non-prerelease, non-devrelease), requires PR > max(main, PyPI).
    - sync_version.py: splits PYPI_PROD_API vs PYPI_TEST_API. Stable
      auto-bumps now use prod PyPI as the floor via
      find_next_stable_patch_version(). The .devN flow keeps using
      TestPyPI. New 'already bumped but ≤ PyPI' path auto-corrects the
      version when somebody bumps to a stale number.
    flowstate authored May 22, 2026
    Configuration menu
    Copy the full SHA
    8b668fd View commit details
    Browse the repository at this point in the history
  2. Fix stale didYouMean props (#81)

    * test: failing regression for stale didYouMean props
    
    * fix(issues): drop stale didYouMean props, add detectedAt
    
    Resolves CUS2-5. The didYouMean class declared four props
    (alternatePackage, downloads, downloadsRatio, editDistance) but the
    current OpenAPI schema (socket-sdk-js/openapi.json:9298) only emits
    { alternatePackage, detectedAt }. The three stale keys were dead at
    runtime and detectedAt was missing a human-readable label entirely.
    Updated to match the schema.
    
    * chore(release): bump to 3.1.1 and sync pyproject.toml
    
    Run via .hooks/sync_version.py after merging origin/main (now at 3.1.0
    from lelia's purl PR). Keeps pyproject.toml and socketdev/version.py
    in lockstep, as flagged in code review.
    
    * chore: sync uv.lock to 3.1.1
    flowstate authored May 22, 2026
    Configuration menu
    Copy the full SHA
    be87c34 View commit details
    Browse the repository at this point in the history

Commits on Jun 2, 2026

  1. Dependabot hardening + dependency update bundle (#84)

    * Harden Dependabot reviews and bundle dependency updates
    
    Mirrors the Dependabot hardening done in socket-python-cli (#207/#217/#218),
    adapted to this SDK (no Dockerfile, no e2e fixtures, hatch/pip build path).
    
    Bundle dependency updates (supersedes 4 open Dependabot PRs):
    - idna 3.11 -> 3.17 (security: CVE-2026-45409 quadratic-time DoS fix)
    - cryptography 46.0.5 -> 46.0.7
    - pygments 2.19.2 -> 2.20.0
    - uv 0.9.21 -> 0.11.17
    
    Verified via uv sync --locked, import smoke, and pytest tests/unit (102 passed).
    
    Adds grouped/cooldowned dependabot.yml (uv + github-actions), a
    dependabot-review workflow running anonymous Socket Firewall smoke jobs,
    Version Check / PR Preview skips for Dependabot PRs, and setup-sfw /
    setup-hatch composite actions.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * chore(release): bump to 3.1.2
    
    Version Check requires a package-version increment on maintainer PRs, and
    this PR bundles dependency bumps + Dependabot hardening. Bump version.py,
    pyproject.toml, and the uv.lock project version in sync.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * Extend dependency review to maintainers (free + enterprise SFW)
    
    Broaden dependabot-review into dependency-review so the Socket Firewall
    guardrail covers maintainer PRs too, not just Dependabot:
    
    - inspect now runs on every PR and computes the SFW edition per-PR:
      enterprise for a trusted SocketDev member (author_association OWNER/
      MEMBER/COLLABORATOR) on an in-repo (non-fork) PR when SOCKET_API_TOKEN
      is present; free (anonymous) for Dependabot, forks, external
      contributors, or when the token is absent.
    - The mode degrades to free whenever the token is missing, so this is
      safe to ship before the secret exists and auto-upgrades to enterprise
      once SOCKET_API_TOKEN is added (repo or org level). The SDK has no
      Socket token today (cf. socket-python-cli's SOCKET_CLI_API_TOKEN).
    - setup-sfw composite action gains `mode` + `socket-token` inputs,
      forwarded to socketdev/action (same action, firewall-free vs
      firewall-enterprise).
    - Rename workflow dependabot-review.yml -> dependency-review.yml to match
      the broadened scope (not a required status check).
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(dependency-review): use runner Python, forbid uv interpreter download
    
    .python-version pins 3.12.7; setup-python provides 3.12.13, so `uv sync`
    tried to download the exact managed CPython from GitHub, which Socket
    Firewall's TLS interception blocked (UnknownIssuer). Set UV_PYTHON=3.12 +
    UV_PYTHON_DOWNLOADS=never so uv uses the runner interpreter and only PyPI
    package fetches route through sfw.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(dependency-review): require strict org membership for enterprise SFW
    
    Tighten the enterprise-mode gate to author_association OWNER/MEMBER only.
    Outside collaborators (COLLABORATOR) now fall through to the free edition,
    same as Dependabot / forks / external contributors.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * chore(dependency-review): rename enterprise secret to SOCKET_SFW_API_TOKEN
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(dependency-review): scope SFW token to a dedicated environment
    
    Resolve zizmor secrets-outside-env (medium) without suppressing it. Split
    the single mode-switching smoke job into two:
    
    - python-sfw-smoke-free: untrusted PRs (Dependabot, forks, outside
      collaborators, externals). Anonymous free edition, never references the
      token.
    - python-sfw-smoke-enterprise: SocketDev org members (OWNER/MEMBER) on an
      in-repo PR. Authenticated enterprise edition; SOCKET_SFW_API_TOKEN is
      scoped to the `socket-firewall` GitHub environment, so only this job can
      read it.
    
    inspect now classifies PR trust (author_association OWNER/MEMBER, non-fork,
    non-Dependabot) and references no secret. No required-reviewer protection
    on the environment, so trusted dep PRs still run automatically.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(dependency-review): gate enterprise on write-access (non-fork), not author_association
    
    author_association only reflects PUBLIC org membership, so private members
    (the common case here) show as CONTRIBUTOR and were misclassified -> the
    enterprise job always skipped. Switch the trust gate to "non-fork PR and not
    Dependabot": only accounts with write access can push an in-repo branch, the
    same boundary GitHub uses for secret exposure. No read:org token needed.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * ci(dependency-review): upload SFW smoke artifacts
    
    * ci(dependency-review): include SFW JSON report artifact
    
    * ci(dependency-review): read SFW report path from env var, drop stdout scrape
    
    Match socket-python-cli: discover the firewall report via the
    $SFW_JSON_REPORT_PATH env var that socketdev/action exports, instead of
    parsing the 'sfw report written to:' line out of stdout.
    
    The two sync steps return to plain 'set -o pipefail' + tee. A new
    'Collect SFW JSON report' step (if: always(), before each upload) copies
    $SFW_JSON_REPORT_PATH into sfw-artifacts/sfw-report.json -- copy, not
    move, since socketdev/action's post step reads that temp path for its job
    summary -- and drops a sfw-report-missing.txt breadcrumb when absent.
    
    More robust than scraping an undocumented log string, and keeps the
    report-capture pattern uniform across both repos.
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    ---------
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
    lelia and claude authored Jun 2, 2026
    Configuration menu
    Copy the full SHA
    8dfb7a1 View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump the python-minor-patch group with 2 updates (#88)

    Bumps the python-minor-patch group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [pytest-cov](https://github.com/pytest-dev/pytest-cov).
    
    
    Updates `ruff` from 0.14.10 to 0.15.14
    - [Release notes](https://github.com/astral-sh/ruff/releases)
    - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/ruff@0.14.10...0.15.14)
    
    Updates `pytest-cov` from 7.0.0 to 7.1.0
    - [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
    - [Commits](pytest-dev/pytest-cov@v7.0.0...v7.1.0)
    
    ---
    updated-dependencies:
    - dependency-name: ruff
      dependency-version: 0.15.14
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    - dependency-name: pytest-cov
      dependency-version: 7.1.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 2, 2026
    Configuration menu
    Copy the full SHA
    64d5b06 View commit details
    Browse the repository at this point in the history

Commits on Jun 3, 2026

  1. feat: add OTHER category to SocketCategory enum (CE-225) (#85)

    The Socket backend returns "other" as an alert category. Since v3.0.33
    (commit 065407a, #79) the SDK tolerates unknown categories via a
    try/except fallback in SocketAlert.from_dict, but that path logs a
    warning that confused customers (Anthropic/Buildkite, FINRA/GitLab CI)
    into reporting it as a crash.
    
    Add OTHER = "other" so the value is recognized as a first-class category
    and the warning no longer fires. The defensive fallback is retained for
    any future unknown categories. Bump to 3.2.0 and sync uv.lock.
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    lelia authored Jun 3, 2026
    Configuration menu
    Copy the full SHA
    8ffef98 View commit details
    Browse the repository at this point in the history
  2. ci(deps): bump actions/setup-python from 5.2.0 to 6.2.0 (#86)

    * ci(deps): bump actions/setup-python from 5.2.0 to 6.2.0
    
    Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.2.0 to 6.2.0.
    - [Release notes](https://github.com/actions/setup-python/releases)
    - [Commits](actions/setup-python@f677139...a309ff8)
    
    ---
    updated-dependencies:
    - dependency-name: actions/setup-python
      dependency-version: 6.2.0
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    * Add version number as comment
    
    * Add version number as comment
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    dependabot[bot] and lelia authored Jun 3, 2026
    Configuration menu
    Copy the full SHA
    7fdb3ac View commit details
    Browse the repository at this point in the history
  3. ci(deps): bump actions/github-script from 7.0.1 to 9.0.0 (#87)

    * ci(deps): bump actions/github-script from 7.0.1 to 9.0.0
    
    Bumps [actions/github-script](https://github.com/actions/github-script) from 7.0.1 to 9.0.0.
    - [Release notes](https://github.com/actions/github-script/releases)
    - [Commits](actions/github-script@60a0d83...3a2844b)
    
    ---
    updated-dependencies:
    - dependency-name: actions/github-script
      dependency-version: 9.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    * Add version number as comment
    
    * Add version number as comment
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    dependabot[bot] and lelia authored Jun 3, 2026
    Configuration menu
    Copy the full SHA
    6beea88 View commit details
    Browse the repository at this point in the history
  4. Add sfw aggregator gate to enforce required CI checks (#89)

    * ci: add Socket Firewall aggregator gate; bump 3.2.0 -> 3.2.1
    
    Add a single sfw-gate job (if: always(), needs the conditional inspect +
    free/enterprise smoke + workflow-notice jobs) that fails only when an
    upstream job failed or was cancelled -- success and skipped both pass.
    
    This is the check intended to become the required status check on main:
    the smoke jobs are conditional (deps-changed gates them, and exactly one
    of free/enterprise runs per PR), so none can be required directly -- a
    required check whose job is if-skipped is never created and blocks merge
    forever. The gate is green when no deps change and is satisfied by
    whichever smoke path actually ran.
    
    NOT yet wired into branch protection -- added during a soak period so the
    check is visible before it becomes blocking, and so requiring it doesn't
    strand other open PRs.
    
    Pattern adapted from SocketDev/socket-python-cli #224.
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * ci: spell out 'iff' as 'if and only if' in gate comment
    
    Review feedback: 'iff' read as a typo. It is the logic shorthand for
    'if and only if', but the comment exists to communicate, so spell it out.
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    ---------
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    lelia authored Jun 3, 2026
    Configuration menu
    Copy the full SHA
    836936c View commit details
    Browse the repository at this point in the history

Commits on Jun 10, 2026

  1. Add transient-error classification to APIFailure (#93)

    * Add transient-error classification to APIFailure
    
    API.do_request now records the HTTP status code on every exception it
    raises (status_code attribute), and APIFailure gains
    is_transient_error(): True for gateway/connection-level failures
    (HTTP 408/502/503/504, dropped or reset connections, client-side
    timeouts) where retrying the same request may succeed, False for
    deterministic errors (400/401/403/404/429, wrapped unexpected errors).
    
    Classification is based on the recorded status code rather than
    exception class identity or message text, so it stays correct if a
    status code gains a dedicated subclass later.
    
    Motivated by SocketDev/socket-python-cli#232: the CLI retries transient
    full-scan upload failures and previously had to parse the status code
    out of catch-all APIFailure message text.
    
    * Hardcode 502 in APIBadGateway instead of accepting a status_code
    
    The class definitionally represents a 502, so there is no reason for
    construction sites to pass (or be able to override) the status.
    mtorp authored Jun 10, 2026
    Configuration menu
    Copy the full SHA
    273ee88 View commit details
    Browse the repository at this point in the history
Loading