Skip to content

chore(ci): bump socket-registry actions to 444b6415 (scan auto-skip)#1262

Merged
John-David Dalton (jdalton) merged 1 commit intomainfrom
chore/registry-sha-bump-13684cd8
Apr 24, 2026
Merged

chore(ci): bump socket-registry actions to 444b6415 (scan auto-skip)#1262
John-David Dalton (jdalton) merged 1 commit intomainfrom
chore/registry-sha-bump-13684cd8

Conversation

@jdalton
Copy link
Copy Markdown
Contributor

@jdalton John-David Dalton (jdalton) commented Apr 22, 2026

Bumps SocketDev/socket-registry action/workflow pins to 444b6415.

Rolls up all three successive cascades into a single pin bump:

  1. tool-envs (7ca50837): setup/action.yml exports SOCKET_TOOL_PNPM_*, SOCKET_TOOL_SFW_*, SOCKET_TOOL_ZIZMOR_*, SOCKET_TOOL_AGENTSHIELD_*, SOCKET_TOOL_NODE_VERSION. @socketsecurity/lib resolvability guard + AgentShield install via downloadPackage.
  2. checksums-file (fd589015): setup/action.yml adds SOCKET_TOOL_CHECKSUMS_FILE env var pointing at a stable on-runner copy of external-tools.json, usable as a Docker build-context COPY source so Dockerfiles can verify pnpm/zizmor/etc. tool checksums without duplicating per-platform SHAs.
  3. matrix scan auto-skip (444b6415): zizmor + ecc-agentshield installs now auto-skip in matrix test cells via strategy.job-total < 2. No user-facing input — PR authors cannot disable scans via workflow inputs. Scans still run exactly once in single-cell jobs (check / lint / type-check).

Mechanical bump; no consumer code changes in this repo.

@jdalton
Copy link
Copy Markdown
Contributor Author

bugbot run

Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 16185f0. Configure here.

@jdalton John-David Dalton (jdalton) force-pushed the chore/registry-sha-bump-13684cd8 branch from 16185f0 to 107055c Compare April 24, 2026 15:56
@jdalton John-David Dalton (jdalton) changed the title chore(ci): bump socket-registry actions to 13684cd8 (gh telemetry opt-out) chore(ci): bump socket-registry actions to 7ca50837 (tool-envs cascade) Apr 24, 2026
@jdalton John-David Dalton (jdalton) force-pushed the chore/registry-sha-bump-13684cd8 branch 2 times, most recently from 7f61fe6 to bcbf5ec Compare April 24, 2026 16:31
@jdalton John-David Dalton (jdalton) changed the title chore(ci): bump socket-registry actions to 7ca50837 (tool-envs cascade) chore(ci): bump socket-registry actions to fd589015 (SOCKET_TOOL_CHECKSUMS_FILE) Apr 24, 2026
@jdalton John-David Dalton (jdalton) force-pushed the chore/registry-sha-bump-13684cd8 branch from bcbf5ec to cbbd5a1 Compare April 24, 2026 17:06
@jdalton John-David Dalton (jdalton) changed the title chore(ci): bump socket-registry actions to fd589015 (SOCKET_TOOL_CHECKSUMS_FILE) chore(ci): bump socket-registry actions to 444b6415 (scan auto-skip) Apr 24, 2026
@jdalton John-David Dalton (jdalton) force-pushed the chore/registry-sha-bump-13684cd8 branch from cbbd5a1 to 836de11 Compare April 24, 2026 20:01
@jdalton John-David Dalton (jdalton) merged commit 69b65b0 into main Apr 24, 2026
8 checks passed
@jdalton John-David Dalton (jdalton) deleted the chore/registry-sha-bump-13684cd8 branch April 24, 2026 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants