chore: sync published workspace versions - #502
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
|
I reviewed the current head No blocking issues found. This looks like a straightforward published-version sync across the infra packages and Checks I performed:
One minor process note: GitHub currently shows the PR green for Socket/Sonar, but I did not see the full workspace CI matrix on this PR view. Given this touches runtime infra dependency locks, I would want either the normal infra/package CI evidence or confirmation that this automation PR intentionally only requires the scanner checks. Subject to that CI/process confirmation, this looks fine to merge. |



Program and scope
Impact
Affected services and intended patch versions are the changed infra package manifests in this PR.
Verification
Security and dependencies
Dependency evidence
Release and operations
The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.
Completion evidence