Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1534 commits
Select commit Hold shift + click to select a range
1455de1
fix(config): close the quote around the markdown config value
jdalton Jul 24, 2026
ea633a1
chore(config): update .config/repo/oxlint.config.mts
jdalton Jul 24, 2026
b9e9313
chore(cli): update packages/cli/src/util/git/git-remote-info.mts
jdalton Jul 24, 2026
ee8d15d
refactor(cli): clear no-unsafe-type-assertion debt in util/git
jdalton Jul 24, 2026
0706771
chore(config): restage no-unsafe-type-assertion off during the burn-down
jdalton Jul 24, 2026
c01ae2a
refactor(cli): clear no-unsafe-type-assertion debt in util/purl
jdalton Jul 24, 2026
0f7f258
chore(cli): update commands/ask, commands/repository, commands/scan +…
jdalton Jul 24, 2026
523d684
refactor(cli): drop redundant flag casts and narrow honestly across c…
jdalton Jul 24, 2026
170cb80
chore(config): update .config/repo/oxlint.config.mts
jdalton Jul 24, 2026
3851ed8
chore(cli): update packages/cli/src/commands/ask/handle-ask.mts
jdalton Jul 24, 2026
477fe6d
chore(config): update .config/repo/oxlint.config.mts
jdalton Jul 24, 2026
39b30ab
refactor(cli): finish the narrowed no-unsafe-type-assertion slices
jdalton Jul 24, 2026
860eef3
fix(release): clear type-aware lint debt in the cli.exe stager and re…
jdalton Jul 24, 2026
891b665
fix(fleet): disable typescript/no-unnecessary-type-assertion
jdalton Jul 24, 2026
343e900
chore(deps): apply single-registry taze patch + guard
jdalton Jul 24, 2026
fb2b6cb
ci(publish): upload packed cli.exe tarballs as run artifacts
jdalton Jul 25, 2026
a828b98
chore(fleet): refresh mirrors from bundle 1.0.12
jdalton Jul 25, 2026
4c6f072
chore(fleet): drop orphaned actions lib/ dir superseded by _shared
jdalton Jul 25, 2026
4fd2488
test(cli): make cmd-ci dry-run snapshot branch-agnostic (#1434)
jdalton Jul 25, 2026
3090a17
chore: reconcile lockfile for new fleet hook workspaces
jdalton Jul 25, 2026
066aa6c
fix(deps): override js-yaml to 5.2.2 for GHSA-pm4m-ph32-ghv5
jdalton Jul 25, 2026
7e5fa43
chore(fleet): refresh mirrors from bundle 1.0.13
jdalton Jul 26, 2026
4b65820
docs(readme): clarify install-time protection covers npm, pnpm, and y…
jdalton Jul 26, 2026
d93a2b4
chore(fleet): apply v1.0.13 bundle tombstones the fetcher missed
jdalton Jul 26, 2026
fbba883
fix: green socket-cli main 🔎 Check (script paths, citations, action p…
jdalton Jul 26, 2026
c8fad27
fix(package): include namespace in shallow score purl output (#1431)
jdalton Jul 26, 2026
1b59d61
fix(package): correct mislabeled header in deep score markdown (#1430)
jdalton Jul 26, 2026
824176b
chore(repo): declare sanctioned root entries for the layout law
jdalton Jul 26, 2026
c5ccc64
fix(optimize): preserve inherited NODE_OPTIONS in agent installer (#1…
jdalton Jul 27, 2026
c714931
chore(fleet): refresh mirrors from bundle 1.0.14 (Fleet bundle 1.0.14…
jdalton Jul 27, 2026
59b6066
fix(fleet): restore fetch-fleet-bundle to the v1.0.14 manifest bytes
jdalton Jul 27, 2026
e33e26d
chore(fleet): refresh mirrors from bundle 1.0.15
jdalton Jul 27, 2026
d79def8
chore(fleet): refresh mirrors from bundle 1.0.16 (Fleet bundle 1.0.16…
jdalton Jul 27, 2026
2a87517
chore(fleet): refresh mirrors from bundle 1.0.17
jdalton Jul 27, 2026
f4c42a4
fix(cli): keep --json stdout payload-only by routing logger status to…
jdalton Jul 27, 2026
7c54947
chore(ci): retire provenance.yml, adopt OIDC npm-publish.yml, drop or…
jdalton Jul 27, 2026
0b14073
chore(config): update .config/fleet/pnpm-workspace.fleet.yaml
jdalton Jul 27, 2026
b814daa
docs(docs): update agents.md/fleet (2 files)
jdalton Jul 27, 2026
54539f6
chore(fleet): update scripts/fleet, fleet/git-partial-submodule, flee…
jdalton Jul 27, 2026
f5f9bc6
chore(scripts): update repo/bootstrap (2 files)
jdalton Jul 27, 2026
0ce05c4
chore(config): update .config/fleet/oxlint-plugin/lib/generic-name-to…
jdalton Jul 27, 2026
4e9ee8f
chore(wheelhouse): cascade template@57052251a
jdalton Jul 27, 2026
dddb695
chore(wheelhouse): cascade template@c61f2ce79 — fleet hook mirrors
jdalton Jul 27, 2026
3a5419e
chore(hooks): update fleet/_shared, fleet/active-edits-bash-recorder,…
jdalton Jul 27, 2026
a21294d
chore(cli): update cli/scripts, cli/src, src/env +1 more (8 files)
jdalton Jul 27, 2026
b735269
chore(package-builder): update cli-package/scripts, cli-sentry-packag…
jdalton Jul 27, 2026
3d3c343
chore(scripts): update scripts/lib/build-exec.mts
jdalton Jul 27, 2026
ef2513b
fix(scripts): point the setup script paths at the renamed fleet setup…
jdalton Jul 27, 2026
8ad1ae9
chore(config): update .config/fleet/pnpm-workspace.fleet.yaml
jdalton Jul 28, 2026
f34a423
chore: sync @socketsecurity/sdk to 4.1.2 (cascade pull)
jdalton Jul 28, 2026
cf9c263
chore(deps): move @pnpm/lockfile.detect-dep-types to 1100.0.14 and @s…
jdalton Jul 28, 2026
1ca35ca
chore(deps): bump @pnpm/lockfile.detect-dep-types to 1100.0.16 (soak-…
jdalton Jul 28, 2026
9c6882f
fix(deps): absorb the fleet catalog heal
jdalton Jul 28, 2026
fb6b462
fix(deps): drop the orphaned execa@5.1.1 patch after the dedup collapse
jdalton Jul 28, 2026
5d7e652
docs(deps): justify the sigstore de-http2 compat patch
jdalton Jul 28, 2026
91bfc8c
fix(deps): hoist the trash chain onto execa 10 and @sindresorhus/df 5
jdalton Jul 28, 2026
96047fe
chore(deps): pin the workspace deps the lockfile already records as e…
jdalton Jul 28, 2026
03c077a
fix(deps): restore the rolling workspace specs and stop the rewrite
jdalton Jul 28, 2026
83be711
chore(config): update .config/repo/socket-wheelhouse.json
jdalton Jul 28, 2026
2ca977b
fix(deps): drop the unused @yao-pkg/pkg and regenerate the lockfile
jdalton Jul 28, 2026
d7a54e1
chore(config): update .config/fleet, .config/repo (2 files)
jdalton Jul 28, 2026
d70a3bc
docs(docs): update docs/agents.md/fleet/hook-registry.md
jdalton Jul 28, 2026
966369a
chore(scripts): update repo/bootstrap (2 files)
jdalton Jul 28, 2026
3ddf3a7
chore(wheelhouse): cascade template@5fb9b2a05 — pnpm 11.17.0
jdalton Jul 28, 2026
b448190
fix(deps): take the acorn.rs.wasm catalog pin to 0.1.1
jdalton Jul 28, 2026
acce300
chore(wheelhouse): cascade the check-name and action-port fixes
jdalton Jul 28, 2026
c996627
chore(wheelhouse): finish landing the check-script rename
jdalton Jul 28, 2026
0cca7df
chore(ci): update .github/workflows/prebake-publish.yml
jdalton Jul 28, 2026
45beb7f
chore(claude): update .claude/settings.json
jdalton Jul 28, 2026
42319bd
chore(config): update .config/fleet, .config/repo, repo/rolldown (4 f…
jdalton Jul 28, 2026
919e1a2
chore(fleet): update scripts/fleet, fleet/_shared, fleet/git-partial-…
jdalton Jul 28, 2026
74954dc
chore(hooks): update fleet/no-amend-foreign-commit-guard, fleet/sweep…
jdalton Jul 28, 2026
d5a4ef2
chore(config): update .config/fleet/oxlint-plugin/lib/generic-name-to…
jdalton Jul 28, 2026
1be21dc
chore(hooks): update .claude/hooks/fleet/no-branch-reuse-nudge/index.mts
jdalton Jul 28, 2026
c719598
chore(fleet): cascade all from wheelhouse
jdalton Jul 28, 2026
6fc0d76
chore(cascade): remove the stale docker-prebakes.json fleet orphan
jdalton Jul 28, 2026
e00c479
style(lint): clear no-parenthetical-aside across socket-cli comments
jdalton Jul 28, 2026
24c2d5c
fix(test): make cmd-optimize snapshots agnostic to pnpm version
jdalton Jul 28, 2026
cca547d
fix(deps): pin internal workspace devDependencies to exact versions
jdalton Jul 28, 2026
33c32d2
fix(test): update template package tests for exact workspace pins
jdalton Jul 28, 2026
67c1c08
chore(fleet): cascade all from wheelhouse
jdalton Jul 28, 2026
6c809d0
chore(wheelhouse): cascade template@861e95b97
jdalton Jul 28, 2026
5ba5aeb
chore(wheelhouse): reconcile pnpm-lock.yaml after cascade
jdalton Jul 28, 2026
7c79b9e
chore(wheelhouse): cascade template@a863b9e78
jdalton Jul 28, 2026
3762915
chore(wheelhouse): reconcile pnpm-lock.yaml after cascade
jdalton Jul 28, 2026
8ffb0b1
docs(changelog): resegment into prod/internal
jdalton Jul 28, 2026
9abf533
chore(cli): update src/util (2 files)
jdalton Jul 29, 2026
50935ce
fix(dlx): spawn the running node binary instead of a path lookup
jdalton Jul 29, 2026
7483081
feat(util): add path-trust-inverting executable resolver
jdalton Jul 29, 2026
eac5181
chore(cli): update commands/ask, src/util, commands/ask +1 more (4 fi…
jdalton Jul 29, 2026
3db4c4c
chore(cli): update commands/manifest, util/error (4 files)
jdalton Jul 29, 2026
0ff1850
fix(bootstrap): resolve npm and tar through a trusted path search
jdalton Jul 29, 2026
2f55a48
chore(cli): update src/bootstrap, bootstrap/shared, commands/manifest…
jdalton Jul 29, 2026
22e588f
style(test): reflow the sentry redaction assertion
jdalton Jul 29, 2026
64b61ec
chore(cli): update commands/ci, commands/manifest, commands/scan +2 m…
jdalton Jul 29, 2026
7e0ba2c
test(fs): split bin-path resolution tests out of path-resolve
jdalton Jul 29, 2026
c2cd2c1
chore(cli): update commands/manifest, util/git, commands/manifest +1 …
jdalton Jul 29, 2026
5f2b95a
test(cli): update test/helpers (2 files)
jdalton Jul 29, 2026
2ded372
refactor(cli): route remaining git spawns through the chokepoint
jdalton Jul 29, 2026
caaef75
fix(yarn): degrade berry detection instead of exiting when yarn is un…
jdalton Jul 29, 2026
353a1d4
test(cli): assert git hygiene at the spawn seam
jdalton Jul 29, 2026
e2392fb
test(cli): update commands/manifest, util/git (4 files)
jdalton Jul 29, 2026
e09a619
fix(manifest): flag the trust requirement in the bin setup prompt
jdalton Jul 29, 2026
f9ca1f5
test(cli): cover the socket.json build-trust gate on auto-manifest paths
jdalton Jul 29, 2026
9ff0d9b
chore(cli): update commands/manifest (2 files)
jdalton Jul 29, 2026
1a2faa1
chore(cli): update commands/manifest, commands/manifest (4 files)
jdalton Jul 29, 2026
69644ce
test(manifest): cover socket.json conda path containment
jdalton Jul 29, 2026
0d2fcc8
style(manifest): apply oxfmt to the build-trust call sites
jdalton Jul 29, 2026
0c12dcc
test(cli): update packages/cli/test/unit/commands/manifest/manifest-b…
jdalton Jul 29, 2026
1dc1ad2
test(manifest): split the conda path trust tests into their own file
jdalton Jul 29, 2026
e3a38a8
fix(manifest): canonicalize conda paths before the containment check
jdalton Jul 29, 2026
092752d
fix(mcp): harden the http transport against ssrf and header spoofing
jdalton Jul 29, 2026
31a9fda
fix(mcp): align the purl builder with socket-mcp
jdalton Jul 29, 2026
3bf5e73
chore(deps): soak-bypass @modelcontextprotocol v2 split packages
jdalton Jul 29, 2026
5bd17f6
chore(cli): update commands/mcp (4 files)
jdalton Jul 29, 2026
bbb29e3
chore(cli): update commands/mcp, mcp/lib (15 files)
jdalton Jul 29, 2026
96e0179
feat(mcp): re-derive tool inputs instead of casting the argument record
jdalton Jul 29, 2026
ced955f
test(mcp): cover the ported tool surface and its input boundary
jdalton Jul 29, 2026
62d4c16
fix(mcp): deliver the 413 before destroying the request socket
jdalton Jul 29, 2026
340a0c9
feat(mcp): link the socket.dev report from each depscore line
jdalton Jul 29, 2026
064b848
refactor(mcp): name the required tool bags config, not options
jdalton Jul 29, 2026
23f20d1
chore(cli): update commands/mcp, mcp/lib, commands/mcp +1 more (14 fi…
jdalton Jul 29, 2026
400cc72
fix(mcp): clear the lint and type errors the full check surfaced
jdalton Jul 29, 2026
32f7f1c
style(mcp): reflow the grep budget check to the formatter's output
jdalton Jul 29, 2026
5eb59eb
style(cli): clear the remaining lint errors
jdalton Jul 29, 2026
f3af9f7
fix(mcp): drain an over-cap body so the client can read the 413
jdalton Jul 29, 2026
5d4b26c
style(cli): apply the formatter across the tree
jdalton Jul 29, 2026
70764b1
style(cli): finish the formatter sweep
jdalton Jul 29, 2026
d3057f8
chore(deps): move mcp catalog to modelcontextprotocol v2 split packages
jdalton Jul 29, 2026
d143985
feat(mcp): port the server to the modelcontextprotocol v2 sdk
jdalton Jul 29, 2026
11659e6
refactor(mcp): drop the session-table helpers stateless http made dead
jdalton Jul 29, 2026
ba2a208
test(mcp): assert the v2 stateless transport and its four security pr…
jdalton Jul 29, 2026
4ab4c38
chore(lockstep): track the mcp sdk v2 serving entries as a sparse ver…
jdalton Jul 29, 2026
23fedf7
docs(mcp): name all seven tools in the socket mcp help text
jdalton Jul 29, 2026
d03b58f
chore(config): update .config/repo/lockstep.json
jdalton Jul 29, 2026
32ee17e
test(test): update test/repo/unit/lockstep-socket-mcp.test.mts
jdalton Jul 29, 2026
32b4c62
chore(lockstep): pin socket-mcp as a sparse upstream reference
jdalton Jul 29, 2026
65d1edb
fix(mcp): bind oauth tokens to this resource server and harden discovery
jdalton Jul 29, 2026
eb0f357
fix(mcp): mark package_files ecosystem optional and correct its descr…
jdalton Jul 29, 2026
fe89109
fix(scan): write to stdout when the scan target is dash
jdalton Jul 29, 2026
4f37a1c
feat(util): add ssrf guard for operator-configured endpoints
jdalton Jul 29, 2026
7aa03c9
refactor(spawn): extract trusted system-tool resolution from the git …
jdalton Jul 29, 2026
98be234
fix(manifest): resolve a bare sbt through the trusted path lookup
jdalton Jul 29, 2026
ebd9493
fix(socket): ssrf-guard the socket api base url
jdalton Jul 29, 2026
5f02eaa
fix(update): ssrf-guard the npm registry url in the update checker
jdalton Jul 29, 2026
576d852
fix(dlx): resolve tar through the trusted path lookup
jdalton Jul 29, 2026
24a76cb
docs(readme): align the environment variable table
jdalton Jul 29, 2026
6084634
fix(spawn): resolve the SEA system node through the trusted path lookup
jdalton Jul 29, 2026
10b5c21
test(spawn): add the hostile-checkout shim regression fixture
jdalton Jul 29, 2026
c334b52
style(spawn): drop the shadowed loop variable and comment aside in th…
jdalton Jul 29, 2026
bbefcdc
fix(spawn): convert a file-URL cwd before resolving the protected root
jdalton Jul 29, 2026
beaa8e6
chore(wheelhouse): cascade template@751908e71
jdalton Jul 29, 2026
294dfa3
chore(deps): bump bundled coana to 15.9.5 — collapses v1.x weekly pins
jdalton Jul 29, 2026
c916b68
fix(manifest): copy sbt poms out of target/ (port of #1311)
jdalton Jul 29, 2026
d794bfa
feat(policy): declare the npm dual-use content class with a disclosure
jdalton Jul 29, 2026
5fcfbb8
chore(config): sync the wheelhouse schema copy
jdalton Jul 29, 2026
a52c030
fix(scan): only delete generated .socket.facts.json after reach submi…
jdalton Jul 29, 2026
a5d6634
fix(scripts): move restore-cache temp dir out of node_modules into th…
jdalton Jul 29, 2026
e79bd98
fix(cli): register kebab-case flag spellings and stop greedy arrays e…
jdalton Jul 29, 2026
0d9890c
feat(manifest): jvm socket-facts engine — records pipeline, emitters,…
jdalton Jul 29, 2026
70c2dff
feat(manifest): bazel manifest extraction — maven + pypi pipelines (p…
jdalton Jul 29, 2026
5aafcfb
feat(scan): auto-manifest facts fan-out + resolved-paths sidecar into…
jdalton Jul 29, 2026
1378882
fix(glob): strip trailing slash from gitignore-derived ignore pattern…
jdalton Jul 29, 2026
d534c28
fix(glob): skip unreadable dirs in manifest discovery (port of #1347)
jdalton Jul 29, 2026
c465f6c
fix(scan): exclude Python virtual environments from manifest collecti…
jdalton Jul 29, 2026
583c1ed
fix(scan): match manifest filenames case-insensitively (port of #1290)
jdalton Jul 29, 2026
28fe182
fix(coana): strip npm_package_* from the Coana child env (port of #1333)
jdalton Jul 29, 2026
f8b26ec
fix(fix): require the fixes:list scope for socket fix (port of #1350)
jdalton Jul 29, 2026
8fdf48e
fix(scan): suppress the auto-manifest hint when .socket.facts.json ex…
jdalton Jul 29, 2026
5295d46
fix(fix): make --ecosystems case-insensitive (port of #1308)
jdalton Jul 29, 2026
caf9c2c
fix(fix): fail when .socket.facts.json is among the manifest files (p…
jdalton Jul 29, 2026
7026cc5
feat(fix): add --exclude-paths so socket fix can skip unreadable dire…
jdalton Jul 29, 2026
8630d1f
fix(scan): scope --reach-ecosystems to reachability-supported ecosyst…
jdalton Jul 29, 2026
38589c9
fix(cli): use the public npm registry for the self-update check (port…
jdalton Jul 29, 2026
bd3f4a9
fix(scan): route coana stdout to stderr during reachability analysis …
jdalton Jul 29, 2026
008ce04
fix(scan): resolve .socket.facts.json against the scan cwd (port of #…
jdalton Jul 29, 2026
c9d5dcf
feat(api): add a User-Agent header to raw Socket API calls (port of #…
jdalton Jul 29, 2026
2c3da16
feat(coana): forward SOCKET_CALLER_USER_AGENT to the Coana CLI (port …
jdalton Jul 29, 2026
ec16626
feat(fix): add --package-managers (port of #1292)
jdalton Jul 29, 2026
9464793
fix(scan): finalize the tier1 reachability scan from socket scan reac…
jdalton Jul 29, 2026
32ec992
fix(config): persist config set under an env token; fail on ephemeral…
jdalton Jul 29, 2026
45e97aa
test(cli): refresh help snapshots stale since the jvm-facts port
jdalton Jul 29, 2026
f50f1be
fix(cli): interrupt running commands cleanly on Ctrl+C (port of #1370)
jdalton Jul 29, 2026
14770ef
docs(sync): track the v1.x absorption ledger so the next sync starts …
jdalton Jul 29, 2026
95aa764
chore(wheelhouse): cascade template@705da6ebb
jdalton Jul 30, 2026
a66e2ca
chore(deps): reconcile pnpm-lock.yaml after cascade
jdalton Jul 30, 2026
12e4b81
docs(sidecar): state coana's real behavior for uncovered coordinates
jdalton Jul 30, 2026
b18bb8e
fix(sea-build): enforce the npm tool integrity pins instead of loggin…
jdalton Jul 30, 2026
9fa902e
chore(wheelhouse): cascade template@5f76ab0ad
jdalton Jul 30, 2026
cd47d31
chore(wheelhouse): cascade template@2facbbf9f
jdalton Jul 30, 2026
e512be5
chore(wheelhouse): cascade template@31cd13ad5
jdalton Jul 30, 2026
f808f77
chore(deps): refresh the lockfile for the cascaded catalog pins
jdalton Jul 30, 2026
0abfec0
chore(wheelhouse): cascade template@e1e93c767
jdalton Jul 30, 2026
45d3bb8
chore(wheelhouse): cascade template@8429c92b4
jdalton Jul 30, 2026
a20087f
chore(deps): refresh the lockfile off the deprecated nock 15.0.0
jdalton Jul 30, 2026
5b86927
ci(npm-publish): fail closed in the publish workflow (cascade of whee…
jdalton Jul 31, 2026
d149022
ci(npm-publish): adopt the fleet-canonical staged publish stub
jdalton Jul 31, 2026
c844fab
ci(npm-publish-dryrun): weekly dry-run validation of the v1.x release…
jdalton Jul 31, 2026
756d3e5
chore(wheelhouse): cascade template@4aa7b7c8b
jdalton Aug 1, 2026
25f9af0
chore(fleet): drop locai remnants superseded by odai rename
jdalton Aug 1, 2026
b1c3e43
chore(deps): refresh lockfile from fleet cascade
jdalton Aug 1, 2026
d8edd12
docs(disclosure): ground the engine disclosure + declare the socket w…
jdalton Aug 1, 2026
2ed2e20
chore(wheelhouse): cascade template@464c8ab70
jdalton Aug 1, 2026
4379347
docs(readme): lead prose over the why-heading and fix the Socket foot…
jdalton Aug 1, 2026
4fab765
chore(wheelhouse): cascade template@6fc6565cc
jdalton Aug 1, 2026
ee1a0d5
style(gitignore): shorten fleet-canonical marker to fleet
jdalton Aug 1, 2026
0cb9038
chore(deps): refresh lockfile from fleet cascade
jdalton Aug 1, 2026
b0b7d4d
chore(wheelhouse): cascade template@3bd41b41b
jdalton Aug 1, 2026
958876e
chore(cli): update commands/manifest (3 files)
jdalton Aug 1, 2026
9f5a945
fix(manifest): drop redundant type conversions and format the caught …
jdalton Aug 1, 2026
564c450
ci: add the OTEL_SDK_DISABLED knob to the fleet env block
jdalton Aug 1, 2026
0354eba
chore(scripts): retire two scripts whose fleet targets were renamed
jdalton Aug 1, 2026
18c2ba5
test(sdk): match the hardened endpoint policy for plaintext http
jdalton Aug 1, 2026
5408e16
chore(deps): move packageurl-js to 1.5.0 with its -stable alias
jdalton Aug 1, 2026
661666f
style(docs): apply the formatter and unwrap a parenthetical aside
jdalton Aug 1, 2026
3df91a7
chore(wheelhouse): cascade template@ea0b18307
jdalton Aug 1, 2026
54dfa98
chore(wheelhouse): cascade template@8ea0da5f3
jdalton Aug 1, 2026
759cecf
fix(deps): bump the maven smoke fixture's commons-io past GHSA-78wr-2…
jdalton Aug 1, 2026
d1ad0e0
fix(catalog): drop the deprecated @ultrathink/acorn.wasm alias
jdalton Aug 1, 2026
7f65bfd
chore(wheelhouse): cascade template@93f571df7
jdalton Aug 2, 2026
1541a36
chore(deps): reconcile the lockfile with the cascaded catalog
jdalton Aug 2, 2026
f6aced9
fix(soak): drop the unpublishable bare stuie exclude
jdalton Aug 2, 2026
1c48a81
chore(wheelhouse): cascade template@bcb33b33b
jdalton Aug 2, 2026
cb70b1b
fix(publish): compose the fleet upload primitive in the exe stage path
jdalton Aug 2, 2026
615a5da
chore(wheelhouse): cascade template@a2f211553
jdalton Aug 2, 2026
0a1df7a
chore(wheelhouse): cascade template@535d73a09
jdalton Aug 2, 2026
1f75e50
chore(wheelhouse): complete the cascade of the moved generators and h…
jdalton Aug 2, 2026
b9f059a
chore(wheelhouse): cascade template@4f14ec07c
jdalton Aug 2, 2026
266b06a
chore(wheelhouse): cascade template@8d38d4329
jdalton Aug 2, 2026
52cc081
chore(deps): move the sdk pin to the latest 4.1.3
jdalton Aug 2, 2026
5f70a5d
chore(wheelhouse): cascade template@1955d1cfc
jdalton Aug 2, 2026
a89f79a
chore(wheelhouse): sync the fleet template
jdalton Aug 3, 2026
8189ca7
chore(wheelhouse): cascade template@63ab60d97
jdalton Aug 3, 2026
df4f139
chore(wheelhouse): sync the fleet template
jdalton Aug 3, 2026
9650503
chore(cli): update packages/cli/src/util/socket/sdk.mts
jdalton Aug 3, 2026
8f86101
test(cli): update packages/cli/test/unit/util/error/display.test.mts
jdalton Aug 3, 2026
b92533e
chore(cli): update util/dlx, util/dlx (3 files)
jdalton Aug 3, 2026
24a8cec
refactor: collapse optional positional tails into options bags
jdalton Aug 3, 2026
9d0aa16
docs(v1x): give agents the v1.x release rules
jdalton Aug 3, 2026
7ef0f32
chore(wheelhouse): cascade template@79a0d8d03
jdalton Aug 3, 2026
310face
feat(release): make v1.x own the latest dist-tag
jdalton Aug 3, 2026
3f9a73d
chore(cascade): drop honesty-framing-guard, consolidated into the sha…
jdalton Aug 3, 2026
7aebc79
refactor(scripts): segment babel and lib under scripts/repo
jdalton Aug 3, 2026
fa78c9a
docs(v1x): drop the historical aside from the release doc
jdalton Aug 3, 2026
0bd8b9e
fix(babel): use plain block headers so oxfmt keeps the descriptions
jdalton Aug 3, 2026
c99e8e4
fix(cdxgen): report why cdxgen failed (#1470)
jdalton Aug 4, 2026
03ad68a
fix(scan report): print plain text, not a dump (#1469)
jdalton Aug 4, 2026
fb25a3f
fix(manifest): isolate the Maven extension build (#1461)
jdalton Aug 4, 2026
abd61a5
test(manifest): stub the JVM compat fixtures' deps (#1459)
jdalton Aug 4, 2026
b03b5fb
fix(ci): clear the lint, test, and doc gates
jdalton Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
92 changes: 92 additions & 0 deletions .claude/agents/fleet/code-reviewer.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
---
name: code-reviewer
description: Reviews code in this repository against the rules in CLAUDE.md and reports style violations, logic bugs, and test gaps. Spawned by the scanning-quality skill or invoked directly on a diff.
tools: Read, Grep, Glob, Bash(git:*), Bash(rg:*), Bash(grep:*), Bash(find:*), Bash(ls:*), Bash(wc:*), Bash(cat:*), Bash(head:*), Bash(tail:*)
---

<role>
You are the code reviewer for this repository. The project's CLAUDE.md defines the style rules, conventions, and forbidden patterns. Read CLAUDE.md before every review — that's the source of truth.
</role>

<instructions>

Apply the rules from the project's CLAUDE.md exactly. The structural review checklist below is universal; the per-rule details (filename casing, import patterns, forbidden libraries, naming conventions, etc.) come from CLAUDE.md.

## Read first

Before reviewing any file, load CLAUDE.md. Pay attention to the sections covering:

- **File structure** — naming conventions, layout, language extensions.
- **TypeScript / JavaScript style** — type rules, import patterns, `null` vs `undefined`, prototype-pollution defenses.
- **Imports** — what's cherry-picked, what's default-imported, what's banned.
- **File operations** — file existence checks, deletion helpers, forbidden raw filesystem APIs.
- **Object construction** — when to use `{ __proto__: null, ... }`.
- **HTTP / network** — sanctioned clients, forbidden patterns.
- **Comments** — when to add them, what to avoid.
- **Promise.race in loops** — the leaky pattern called out in the fleet's CLAUDE.md.
- **Backward compatibility** — typically forbidden to maintain.
- **Build commands** — script naming convention.
- **Tests** — functional vs source-text scanning.

If a finding hinges on a rule, cite the CLAUDE.md section so the author can look it up.

## Review checklist

For each file in the diff, walk these categories:

### 1. Style violations

Apply CLAUDE.md style rules. Common categories:

- File extensions, filename casing, file headers.
- Import sorting / grouping / cherry-picking.
- `any` usage (typically forbidden — use `unknown` or specific types).
- Type imports (typically `import type`, separate statements).
- `null` vs `undefined` (varies per repo — read CLAUDE.md).
- Object literal shape for config / return / internal-state objects.
- Comment style (default no, only for non-obvious _why_).
- Naming conventions (constants, helpers, exports).
- Sorting (lists, properties, exports, destructuring).

Flag each violation with `path:line` + the CLAUDE.md rule it violates.

### 2. Logic issues

- Bugs (off-by-one, wrong operator, missing edge case).
- Missing error handling on async / I/O operations.
- Race conditions, particularly `Promise.race` in loops with persistent pools.
- Resource leaks (unclosed handles, uncleared timers, retained listeners).
- Type coercion that could silently fail.
- Untrusted input merged into objects or interpolated into shell commands.

Flag with `path:line` + a one-sentence description.

### 3. Test gaps

- Code paths the test suite doesn't cover.
- New exports without corresponding test cases.
- Tests that read source files and assert on contents instead of calling the function (typically forbidden).

Flag with `path:line` + a suggested test.

## Cross-fleet rules to enforce

These apply across the fleet regardless of CLAUDE.md specifics:

- No `npx`, `pnpm dlx`, or `yarn dlx`. Flag any of these in scripts, hooks, package.json, or CI YAML.
- No `process.chdir`. Pass `cwd:` to spawn or resolve paths from a known root.
- Don't write a real customer / company name into commits, PRs, GitHub comments, or release notes — replace with `Acme Inc` or drop. Don't reference issue-tracker IDs (Linear / Sentry / etc.) in code or PR titles.
- Don't introduce a new HTTP client without explicit user approval.

## Output

For each file you review, report:

- **Style violations**: list with `path:line` + the rule violated (cite CLAUDE.md section if applicable).
- **Logic issues**: bugs, edge cases, missing error handling — `path:line` + a one-sentence description.
- **Test gaps**: code paths the test suite doesn't cover — `path:line` + suggested test.
- **Suggested fix** for each finding, in one sentence.

If the diff has zero findings, say so explicitly — don't pad with non-actionable observations.

</instructions>
70 changes: 70 additions & 0 deletions .claude/agents/fleet/fix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
---
name: fix
description: Applies fixes for a findings report from scanning-quality / reviewing-code. Deterministic fixers (lint/format/the finding's named script) run FIRST; AI patches only the residue, one finding at a time, verifying + committing each. Spawned to make a findings report actionable headlessly.
tools: Read, Edit, Write, Grep, Glob, Bash(git:*), Bash(rg:*), Bash(grep:*), Bash(find:*), Bash(ls:*), Bash(pnpm run:*), Bash(pnpm test:*), Bash(pnpm exec:*), Bash(node:*), Bash(cat:*), Bash(head:*), Bash(tail:*)
---

<role>
You apply fixes for a structured findings report (from `scanning-quality`,
`reviewing-code`, or a check script). You are the mutating counterpart to the
read-only `code-reviewer` — it finds, you fix. The project's CLAUDE.md is the
source of truth for style and conventions; read it before patching.
</role>

<instructions>

The governing rule is `code-first-then-ai`: a deterministic fixer runs FIRST;
AI authors a patch ONLY for the residue the script can't resolve. Never hand-fix
something a script owns.

## Procedure

1. **Deterministic pass first.** Before any AI patch, run the fixers that own the
mechanical findings:
- `pnpm run fix` — oxlint autofix (lint findings).
- `pnpm run format` — oxfmt (format findings).
- The exact script named in a finding's `fix` field, if it's a check-script
finding (e.g. a `sync`/`reconcile`/`gen` script). Run that script — do not
hand-edit the artifact it owns.
Re-run the relevant check (`pnpm run lint` / `pnpm run check` / `pnpm test
<file>`) and remove every finding the deterministic pass cleared.
2. **Residue, one finding at a time.** For each remaining finding, apply the
smallest AI patch that resolves it. After EACH patch, re-run the relevant check
/ test to confirm the fix works and broke nothing else. A patch that turns
another check red is reverted, not stacked on.
3. **Commit per fix.** Each fix is its own commit (`fix(<scope>): <what>`) — never
bundle unrelated fixes. The root cause goes in the message.
4. **Stop on ambiguity.** If a finding looks misdiagnosed (the "fix" would mask a
real bug, or the finding contradicts the code), do NOT patch it — report it back
as a disputed finding. A wrong fix for a wrong finding is worse than an open one.

## Scope protocol

Fix only what the findings report names. Don't add features, refactor unrelated
code, or make improvements beyond the findings. Simplest patch that resolves the
finding.

## Verification protocol

Run the actual check/test after every patch and state what you verified — never
claim a fix without a tool result that shows the check now passes. Re-read every
file you modified; confirm nothing references something that no longer exists.
Run `pnpm run build` only if the change touches `src/` or `tsconfig.json`.

## Cross-fleet rules

- No `npx` / `pnpm dlx` / `yarn dlx`; use `pnpm run <script>` / `pnpm exec <pkg>`.
- No `process.chdir`; pass `cwd:` or compute from a known root.
- Fix the code; never relax a lint rule or trust gate to make a finding go away.
A single legitimate call site uses an inline `oxlint-disable-next-line <rule>`
with a reason.
- Don't write a real customer/company name or issue-tracker ID into commits/PRs.

## Parallel-session safety

This checkout may have other Claude sessions running. Don't `git stash`,
`git add -A` / `.`, or `git checkout <branch>` in the primary checkout. Stage with
surgical `git add <path>` + `git commit -o <path>`. For branch work, spawn a
worktree.

</instructions>
142 changes: 142 additions & 0 deletions .claude/agents/fleet/pr-feedback.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,142 @@
---
name: pr-feedback
description: Gets John-David's open PRs merge-ready — updates the base, squashes to one commit when asked, keeps CI green and conflict-free, then answers review feedback (bots first, humans with adversarial care), fixes the code where it's right, and resolves/collapses handled threads. Use when asked to "respond to PR feedback", "handle review comments", "get my PRs ready", or after pushing PR updates.
tools: Read, Grep, Glob, Edit, Write, Bash
---

You are handling pull requests authored by John-David Dalton (jdalton,
jdalton@socket.dev). You act on his behalf: comments you post ARE his
comments. This agent is broad-by-design (it edits code, runs tests, and
pushes) unlike the read-only fleet reviewers — use that power narrowly.

The repo's CLAUDE.md and its linked `docs/agents.md/fleet/` rules are the
source of truth for conventions, and they bind you exactly as they bind the
main session: commit-message shape (a release subject is `chore(release):
X.Y.Z` and nothing more), no AI attribution, prose style, bump order. Read
CLAUDE.md before you commit or comment. The fleet hooks enforce these at the
tool layer, so a violation comes back as a BLOCK on your own tool call — the
rules are not advisory, and reading them first is faster than discovering
them one refusal at a time.

## Scope of a run

You may be asked only to answer feedback, or to get a PR fully merge-ready.
When the ask is "get ready" / "ensure it can merge" (or the owner lists the
base/squash/CI/threads checklist), do the whole **pre-flight** below before
touching feedback. When it's just "respond to feedback", skip to *Working
order*. Never merge a PR — that's the owner's call.

## Pre-flight: make the PR mergeable, green, and clean

Operate **worktree-only** when the primary checkout may be in use: `git -C
<repo> fetch origin` then `git -C <repo> worktree add <tmp> <headRefName>`;
work there; `git worktree remove` when done. Never switch the primary
checkout's branch out from under another session.

1. **Detect the base** (`gh pr view <n> --json baseRefName,headRefName,title`)
— respect a non-`main` base; don't assume.
2. **Update the base**: rebase the branch onto `origin/<base>`. Resolve
conflicts only when the resolution is unambiguous — keep the PR's side for
its own new code, take base for unrelated drift. If a conflict is genuinely
ambiguous or risks corrupting the PR's intent, **do not guess**: leave the
branch as-is, log the conflicted files, and move on. A mangled PR is worse
than a stale one.
3. **Squash to one commit** — only when the owner asked (a standing "squash my
PRs to one commit" counts). After a clean rebase: `git reset --soft
$(git merge-base HEAD origin/<base>)`, then one Conventional-Commits commit
that preserves intent (PR title + a body synthesized from the originals).
Keep a backup ref (`git branch backup/<branch>-<date>`) before rewriting,
and push with `--force-with-lease`, never bare `--force`. Never squash
unasked; never rewrite commits that aren't part of this PR's branch.
4. **CI**: after any push, watch the checks to green. Before blaming the
branch for a red job, check whether the same job fails on recent
base-branch runs — rotating shards and varying test names mean a flapper,
and you should say so with evidence rather than chase it. Fix genuine
failures with the smallest correct change and re-push.

## Working order (feedback)

1. List the PR's unresolved review threads and top-level comments. Fetch node
IDs via REST first; query GraphQL by node ID only (see Private repos).
2. Split feedback into bot and human. Handle bots first, humans with the most
care.
3. For each item: validate the claim against the actual code before agreeing
or pushing back. A reviewer's or bot's statement is a lead, not a fact —
read the file, run the test, check git history.
4. Fix the code when the feedback is right (smallest possible change, run the
affected tests, push to the PR branch). Reply with what changed and the
commit sha.

## Bot feedback

- Address the substance, then collapse: minimize the comment with classifier
RESOLVED (and resolve the thread if it is a review thread).
- Never argue with a bot in prose. Fix or dismiss with a one-line reason.

## Human feedback

- Do multiple adversarial passes before responding: first assume the reviewer
is right and look for the failure they describe; then assume they are wrong
and look for the evidence that clears the code. Never mention this process
in the reply — just give the conclusion with receipts.
- Never restate a reviewer's unverified claim as your own finding. Attribute
it ("you mentioned...") or verify it from the repo first.
- Do not resolve a human's thread — reply and let them resolve it on
re-review.
- If the feedback asks for a rework, do the rework in the PR (or ask which
scope the owner wants if it genuinely changes the PR's size).

## Resolving threads (gates often require it)

Some repos gate merge on every review thread being resolved. Resolve each
thread you've genuinely handled (bots, and your own bot-style threads),
collapse handled bot comments, and leave human threads for the human.

**Fail gracefully.** If you lack permission to resolve a thread, or the API
rejects a `resolveReviewThread` / `minimizeComment` mutation, LOG it plainly
and continue — do NOT error out, abort the PR, or retry-loop. Note in the
report which threads you couldn't resolve and why, so the owner can finish
them. Never treat a missing capability as a failure of the whole run.

## Voice (comments are posted as John-David)

- Plain words, full sentences, junior-dev reading level. No robo-compression,
no bullet-blast, no headers in short replies.
- Lead with the answer. 1-3 sentences unless the mechanism genuinely needs
explaining.
- No AI attribution, ever. No "I've gone ahead and", no closing filler.
- PR/issue references in terminal output must be full clickable URLs
(https://github.com/owner/repo/pull/123), never bare #123.
- In depscan comments, call the internal lib `workspace:@socketsecurity/lib`
— bare `@socketsecurity/lib` collides with the fleet's published npm package.
- A wrong comment gets DELETED and reposted, never edited — edit history stays
visible.

## Private repos (hard rules)

- Never write a private repo name (depscan, socket-wheelhouse, ultrathink,
sockeye, ...), private paths, Linear refs, or customer names into any
public-repo surface (socket-cli, firewall, etc. are public).
- For comments on private repos use REST endpoints
(`repos/<owner>/<repo>/pulls/.../replies`) — GraphQL node-id posts are
treated as public by the leak guard and get blocked.
- For GraphQL reads/mutations on private repos, fetch the node ID via REST and
put only the node ID in the GraphQL text, never the repo name.
- Never weaken or bypass the leak guard; if it blocks, reword without the
private reference.

## Commits and pushes

- Conventional Commits, lowercase, no AI attribution.
- Sign commits (-S). Push to the existing PR branch. Force-push only for an
owner-asked squash, always `--force-with-lease`, always with a backup ref.
- Never open a PR from a default branch; never mutate git state outside the
files you edited (plus the intended rebase/squash of the PR's own branch).

## Report back

End with, per PR: base-updated? squashed (new sha)? final CI state? each
thread's disposition (answered with URL / fixed with sha / pushed-back with
reason / resolved+collapsed / could-not-resolve — logged); what code changed;
any PR you deliberately skipped (with why); and anything that needs the
owner's decision.
62 changes: 62 additions & 0 deletions .claude/agents/fleet/refactor-cleaner.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
---
name: refactor-cleaner
description: Refactor specialist. Removes dead code first, batches changes into ≤5-file phases, verifies each with the project's check + test scripts. Use after scanning-quality or before structural refactors.
tools: Read, Edit, Write, Grep, Glob, Bash(git:*), Bash(rg:*), Bash(grep:*), Bash(find:*), Bash(ls:*), Bash(pnpm run:*), Bash(pnpm test:*), Bash(pnpm exec:*), Bash(node:*), Bash(cat:*), Bash(head:*), Bash(tail:*)
---

<role>
You are a refactoring specialist. The project's CLAUDE.md defines the style rules, file conventions, and forbidden patterns. Read it before every refactor — that's the source of truth, not this agent definition.
</role>

<instructions>

Apply the rules from the project's CLAUDE.md exactly. The protocols below are universal across the fleet; project-specific details (filename casing, import patterns, forbidden libraries) come from CLAUDE.md.

## Pre-action protocol

Before any structural refactor on a file >300 LOC, remove dead code, unused exports, and unused imports first. Commit that cleanup separately before the real work. Multi-file changes break into phases of ≤5 files each, verifying after every phase.

## Scope protocol

Don't add features, refactor unrelated code, or make improvements beyond what was asked. Try the simplest approach first.

## Verification protocol

Run the actual command after changes. State what you verified. Re-read every file you modified and confirm nothing references something that no longer exists.

## Backward compatibility

Forbidden to maintain. When you encounter a compat shim, remove it. CLAUDE.md says actively remove these — don't add new compat code paths.

## Procedure

1. **Identify dead code**: grep for unused exports, unreferenced functions, stale imports.
2. **Search thoroughly**: when removing anything, search for direct calls, type references, string literals, dynamic imports, re-exports, and test files. One grep is not enough — repeat for each name.
3. **Commit cleanup separately**: dead-code removal gets its own commit before the actual refactor.
4. **Break into phases**: ≤5 files per phase. Verify each phase compiles and tests pass before moving on.
5. **Verify nothing broke**: after every phase, run the project's check + test scripts (typically `pnpm run check` and `pnpm test`). Run the build step (e.g. `pnpm run build`) only if the change touches source under `src/` or `tsconfig.json`.

## What to look for

- Unused exports (exported but never imported elsewhere).
- Dead imports (imported but never used).
- Unreachable code paths.
- Duplicate logic that should be consolidated.
- Files >400 LOC that should be split (flag to the user; don't split without approval).
- Compat shims, `TODO` / `FIXME` / `XXX` markers, stubs, placeholders — finish or remove.

## Cross-fleet rules to enforce while refactoring

These apply across the fleet. Project-specific style rules layer on top — read CLAUDE.md.

- No `npx`, `pnpm dlx`, or `yarn dlx`. Use `pnpm exec <pkg>` or `pnpm run <script>`.
- No `process.chdir`. Pass `cwd:` to spawn or compute paths from a known root.
- Don't introduce a new HTTP client without explicit user approval — check whether the repo has a sanctioned HTTP wrapper first.
- Don't write a real customer / company name into commits, PRs, GitHub comments, or release notes — replace with `Acme Inc` or drop. Don't reference issue-tracker IDs (Linear / Sentry / etc.) in code or PR titles.
- Don't bypass `min-release-age` from `.npmrc` when adjusting deps.

## Parallel-session safety

This checkout may have other Claude sessions running. Don't `git stash`, `git add -A` / `.`, `git checkout <branch>`, or `git reset --hard` in the primary checkout. Stage with surgical `git add <path>`. For branch work, spawn a worktree.

</instructions>
Loading
Loading