Skip to content

chore(ci): cascade socket-registry pin to 85a2fc0d#1285

Open
John-David Dalton (jdalton) wants to merge 4 commits intomainfrom
chore/registry-cascade
Open

chore(ci): cascade socket-registry pin to 85a2fc0d#1285
John-David Dalton (jdalton) wants to merge 4 commits intomainfrom
chore/registry-cascade

Conversation

@jdalton
Copy link
Copy Markdown
Contributor

@jdalton John-David Dalton (jdalton) commented Apr 27, 2026

Self-landable split from #1279.

Bumps SocketDev/socket-registry workflow pins from ea1986b8 to 85a2fc0d. Picks up:

  • bootstrap-from-registry step in install/action.yml (pre-seeds @socketsecurity/lib before pnpm install)
  • path-guard fleet cascade

Test plan

  • CI passes

Note

Medium Risk
Medium risk because it changes the pinned versions of shared CI/publish automation (setup-and-install and git-signing actions), which can affect build, test, and release behavior even though no product code changes.

Overview
Bumps the pinned SocketDev/socket-registry action revision across ci.yml, provenance.yml, and weekly-update.yml (from ea1986b8… to 85a2fc0d…).

This updates the versions used for dependency setup/installation and the weekly-update git signing/cleanup steps, aligning CI, publishing, and automation with the newer shared workflow implementation.

Reviewed by Cursor Bugbot for commit 9ef28f8. Configure here.

Picks up the latest socket-registry workflow updates (currently the
bootstrap-from-registry step in install/action.yml + the path-guard
fleet rollout cascade).

Self-landable split from #1279.
Picks up the firewall-checker fix in @SocketDev/socket-registry —
any alert from Socket Firewall now blocks the bootstrap (no severity
threshold; the API only returns alerts when a package is flagged
as malware, so any alert means malware).

Cascade chain:
  check-firewall.mts        Layer 1  e4193847
  setup-and-install         Layer 2  b94c9571
  reusable workflows        Layer 3  85a2fc0d  ← propagation SHA
  _local-not-for-reuse-*    Layer 4  25ec2c76  (socket-registry only)
@jdalton
Copy link
Copy Markdown
Contributor Author

bugbot run

Copy link
Copy Markdown

@cursor cursor Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 9ef28f8. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants