Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: SocketDev/socket-python-cli
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.6.1
Choose a base ref
...
head repository: SocketDev/socket-python-cli
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v2.6.3
Choose a head ref
  • 7 commits
  • 15 files changed
  • 4 contributors

Commits on Aug 7, 2026

  1. Raise failure on SBOM fetch errors (#288)

    * fix(core): raise on SBOM fetch failure instead of writing empty reports (CE-362)
    
    get_sbom_data returned {} when the full-scan stream fetch failed, so
    report generation continued and produced empty GitLab dependency
    scanning, license, and SARIF output with exit code 0. Raise APIFailure
    instead so the failure goes through the CLI's existing API-error
    handling (exit code 3 by default, still exit 0 with
    --disable-blocking).
    
    Bump the socketdev floor to 3.4.2, the bundled release that adds the
    missing purl types (e.g. "generic") and per-artifact parse resilience
    that caused this failure mode. Merge after socketdev 3.4.2 is on PyPI.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * chore: lock socketdev 3.4.2
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * chore: bump version to 2.5.11
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * ci(e2e): retry reachability on empty results, upload diagnostics on failure
    
    The e2e-reachability job intermittently fails with 'no components with
    alerts in .socket.facts.json': the tier-1 reachability backend can
    return empty results while the CLI reports success (ENG-5093), and the
    same flake has hit unrelated PRs.
    
    - Add a retry-probe hook to the e2e matrix: entries that define it get
      up to 3 scan attempts, retrying only when the probe says the output
      looks incomplete. Persistent failures still fail via the validate
      step. Each retry emits a warning annotation and a step-summary line
      so flake frequency stays visible.
    - Add tests/e2e/reach-facts-probe.sh: exits 0 when the facts file has
      alerted components, non-zero (retry) when empty or missing.
    - Upload /tmp/e2e-output.log, SARIF/GitLab outputs, and facts files as
      artifacts when any e2e job fails, so flakes are diagnosable without
      a re-run.
    
    Also bump version to 2.6.2 (2.6.0 and 2.6.1 are being released ahead
    of this PR).
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * chore: require socketdev 3.5.0
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * Drop ticket references from e2e comments and note the retry hardening in the changelog
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * Move e2e retry changelog entry out and drop remaining ticket reference
    
    The e2e retry hardening ships with the dependency pinning PR instead,
    so its changelog entry moves there.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    
    * docs: changelog phrasing tweak
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    ---------
    
    Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
    Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
    lelia and claude authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    29bbc56 View commit details
    Browse the repository at this point in the history
  2. ci(deps): bump actions/setup-python from 6.2.0 to 7.0.0 (#293)

    Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.2.0 to 7.0.0.
    - [Release notes](https://github.com/actions/setup-python/releases)
    - [Commits](actions/setup-python@a309ff8...5fda3b9)
    
    ---
    updated-dependencies:
    - dependency-name: actions/setup-python
      dependency-version: 7.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    dependabot[bot] and lelia authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    a993c9d View commit details
    Browse the repository at this point in the history
  3. chore(deps): bump twine from 6.2.0 to 7.0.0 in the python-major group (

    …#296)
    
    * chore(deps): bump twine from 6.2.0 to 7.0.0 in the python-major group
    
    Bumps the python-major group with 1 update: [twine](https://github.com/pypa/twine).
    
    
    Updates `twine` from 6.2.0 to 7.0.0
    - [Release notes](https://github.com/pypa/twine/releases)
    - [Changelog](https://github.com/pypa/twine/blob/main/docs/changelog.rst)
    - [Commits](pypa/twine@6.2.0...7.0.0)
    
    ---
    updated-dependencies:
    - dependency-name: twine
      dependency-version: 7.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: python-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    
    * Pin dev and test extras to exact versions
    
    Runtime dependencies were pinned exactly in 2.6.0; this applies the
    same policy to the dev and test extras (matching the currently locked
    versions, including the twine 7.0.0 bump from this PR) so future
    dependency updates surface in pyproject.toml rather than only in
    uv.lock.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
    3 people authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    dd0835e View commit details
    Browse the repository at this point in the history
  4. ci(deps): bump the github-actions-minor-patch group across 2 director…

    …ies with 4 updates (#292)
    
    Bumps the github-actions-minor-patch group with 1 update in the / directory: [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish).
    Bumps the github-actions-minor-patch group with 3 updates in the /.github/actions/setup-docker directory: [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [docker/login-action](https://github.com/docker/login-action).
    
    
    Updates `pypa/gh-action-pypi-publish` from 1.14.1 to 1.14.2
    - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)
    - [Commits](pypa/gh-action-pypi-publish@v1.14.1...dc37677)
    
    Updates `docker/setup-qemu-action` from 4.1.0 to 4.2.0
    - [Release notes](https://github.com/docker/setup-qemu-action/releases)
    - [Commits](docker/setup-qemu-action@0611638...96fe6ef)
    
    Updates `docker/setup-buildx-action` from 4.1.0 to 4.2.0
    - [Release notes](https://github.com/docker/setup-buildx-action/releases)
    - [Commits](docker/setup-buildx-action@d7f5e7f...bb05f3f)
    
    Updates `docker/login-action` from 4.2.0 to 4.6.0
    - [Release notes](https://github.com/docker/login-action/releases)
    - [Commits](docker/login-action@650006c...dbcb813)
    
    ---
    updated-dependencies:
    - dependency-name: pypa/gh-action-pypi-publish
      dependency-version: 1.14.2
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/setup-qemu-action
      dependency-version: 4.2.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/setup-buildx-action
      dependency-version: 4.2.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    - dependency-name: docker/login-action
      dependency-version: 4.6.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: github-actions-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    dependabot[bot] and lelia authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    70bbde9 View commit details
    Browse the repository at this point in the history
  5. ci(deps): bump actions/setup-python in /.github/actions/setup-sfw (#295)

    Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.2.0 to 7.0.0.
    - [Release notes](https://github.com/actions/setup-python/releases)
    - [Commits](actions/setup-python@a309ff8...5fda3b9)
    
    ---
    updated-dependencies:
    - dependency-name: actions/setup-python
      dependency-version: 7.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    dependabot[bot] and lelia authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    1cf2246 View commit details
    Browse the repository at this point in the history
  6. chore(deps): bump the python-minor-patch group with 3 updates (#294)

    Bumps the python-minor-patch group with 3 updates: [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/), [markdown](https://github.com/Python-Markdown/markdown) and [ruff](https://github.com/astral-sh/ruff).
    
    
    Updates `beautifulsoup4` from 4.14.3 to 4.15.0
    
    Updates `markdown` from 3.10.2 to 3.10.3
    - [Release notes](https://github.com/Python-Markdown/markdown/releases)
    - [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
    - [Commits](Python-Markdown/markdown@3.10.2...3.10.3)
    
    Updates `ruff` from 0.16.0 to 0.16.1
    - [Release notes](https://github.com/astral-sh/ruff/releases)
    - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
    - [Commits](astral-sh/ruff@0.16.0...0.16.1)
    
    ---
    updated-dependencies:
    - dependency-name: beautifulsoup4
      dependency-version: 4.15.0
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: python-minor-patch
    - dependency-name: markdown
      dependency-version: 3.10.3
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    - dependency-name: ruff
      dependency-version: 0.16.1
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: python-minor-patch
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
    3 people authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    56181bc View commit details
    Browse the repository at this point in the history
  7. Bump pinned @coana-tech/cli to 15.10.4 (#291)

    * Bump pinned @coana-tech/cli to 15.10.4
    
    * Rev version to 2.6.3, consolidating the unpublished 2.6.2 notes
    
    2.6.1 shipped while this PR was in flight, and the 2.6.2 version bump on
    main was never published. Fold the 2.6.2 changelog entry, the Dependabot
    updates, and the dev/test dependency pinning into the 2.6.3 entry.
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    * Trim dependency-update specifics in the 2.6.3 changelog entry
    
    Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
    
    ---------
    
    Co-authored-by: socket-pr-bot[bot] <294242679+socket-pr-bot[bot]@users.noreply.github.com>
    Co-authored-by: lelia <2418071+lelia@users.noreply.github.com>
    Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
    3 people authored Aug 7, 2026
    Configuration menu
    Copy the full SHA
    974f656 View commit details
    Browse the repository at this point in the history
Loading